Overview of the Yeti Platform
mainYeti is a Forensics Intelligence platform designed to bridge the gap between Cyber Threat Intelligence (CTI) and Digital Forensics and Incident Response (DFIR) practitioners. It provides a pipeline for DFIR teams to search for indicators of compromise (IOCs) within timelines and relate artifacts to known threats.
Key capabilities include:
- Bulk Observable Searching: Identify the nature of a threat and how to locate it on a system based on observables.
- Threat-Centric Analysis: Quickly list TTPs, malware, and related DFIR artifacts associated with a specific threat.
- CTI Enrichment: Allows CTI analysts to focus on intelligence rather than machine-readable export formats.
- Extensibility: Easily incorporate custom data sources, analytics, and logic.
Yeti functions by storing technical and tactical CTI (observables, TTPs, campaigns, etc.), acting as a backend for DFIR-related queries (such as Yara signatures, Sigma rules, and DFIQ), providing a web API for automation, and exporting data in user-defined formats for ingestion by SIEMs or other DFIR platforms.