DFIRe documentation

How to deploy DFIRe, configure it for the way your team works, and use it day to day. If you are installing for the first time, start with the quick start.

Quick start Production deployment

Start here

Quick start

Install with Docker Compose and open your first case.

Configuration

Environment variables, secrets and the settings that matter on day one.

Cases

How a case is structured and how work moves through it.

Evidence

Items, attributes, custody records and printable receipts.

Single sign-on

Connect an OIDC provider and map roles to your groups.

Backup and recovery

Schedules, validation and restoring an instance.

System requirements

Component Small evaluation Production starting recommendation
CPU2 vCPU8 vCPU
RAM4 GB16 GB
Storage20 GB free SSD space100 GB SSD system disk, plus evidence and backup storage
Docker24.0Latest stable
Docker Compose2.24.4Latest stable

These are planning recommendations, not measured capacity limits. Size evidence and backup storage to your caseload and retention requirements. Use a separately managed PostgreSQL 16 or later server for production, with its own resource allocation.

Getting help

The support page covers diagnostics and the support bundle. For anything else, write to [email protected]. Security reports go to the address in our security policy.