Tech riderRev. 20 Sept 2026
- 1Runs onAPI, self-hosted, Web
- 2CostsNot stated by the maker
- 3Indicator enrichmentYes
- 4Workflow automationYes
- 5Deploymentself-hosted
4 lines stated Written from the maker's own pages: yeti-platform.io
Overview
Yeti is ranked #27 of 31 in threat intelligence platforms on Specifiction. It runs on API, Self-hosted, Web.
Compared on threat intelligence platforms
- Free plan
- Yesyeti-platform.io
- Indicator enrichment
- Yesyeti-platform.io
- Workflow automation
- Yesyeti-platform.io
- Deployment
- self-hostedyeti-platform.io
Facts
- Purpose
- Yeti describes itself as a Forensics Intelligence platform and pipeline for DFIR teams, intended to bridge CTI and DFIR practitioners.yeti-platform.io · 9 Oct 2026
- Intelligence management
- Yeti stores and manages DFIQ objects, forensic artifact definitions, Sigma and Yara rules, reusable queries, and technical and tactical CTI.yeti-platform.io · 9 Oct 2026
- Search
- Yeti supports bulk searches of observables and can help identify a threat and how to find it on a system.yeti-platform.io · 9 Oct 2026
- Threat context
- Yeti can list TTPs, malware, and related forensic artifacts for a selected threat.yeti-platform.io · 9 Oct 2026
- Data sources and exports
- Yeti can incorporate user data sources, analytics, and logic, and export data in user-defined formats for third-party SIEM and DFIR applications.yeti-platform.io · 9 Oct 2026
- API
- Yeti provides a REST API, including endpoints for importing observables from text, files, and URLs.yeti-platform.io · 9 Oct 2026
- Installation
- The documented supported installation method uses dedicated Docker containers and requires Git, Docker, and the Docker Compose plugin.yeti-platform.io · 9 Oct 2026
- Web interface
- The getting-started guide runs Yeti on a server and opens its web interface at localhost on port 80.yeti-platform.io · 9 Oct 2026
- Integration example
- Yeti documents a GitHub Monitor plugin that uses a GitHub token and a GitHub query type.yeti-platform.io · 9 Oct 2026
- Threat intelligence
- It stores technical and tactical CTI, including observables, TTPs, and campaigns, from internal or external systems.yeti-platform.io · 9 Oct 2026
- Data model
- Yeti organizes information as observables, entities, and indicators, which can be linked into threat graphs.yeti-platform.io · 9 Oct 2026
- Indicators
- Indicators can match observables and apply tags; the web UI supports text-based Regex and Yara matching, while Query and Sigma indicators are intended for automation with other systems.yeti-platform.io · 9 Oct 2026
- Automation
- Python tasks support scheduled or on-demand analytics and feeds, while exports can select observables and render them to disk with a Jinja template.yeti-platform.io · 9 Oct 2026
- Enrichment
- The documentation gives VirusTotal data enrichment as an analytics example and says analytics can be extended with private scripts.yeti-platform.io · 9 Oct 2026
- Integrations
- Yeti describes exporting data in user-defined formats for ingestion by third-party SIEM and DFIR applications.yeti-platform.io · 9 Oct 2026
- Timesketch
- Yeti documentation describes using Query indicators with Timesketch sketches and tagging matching events.yeti-platform.io · 9 Oct 2026
- Open source
- The project’s GitHub repository identifies its license as Apache-2.0.github.com · 9 Oct 2026
- MISP collaboration
- Yeti and the MISP Project announced collaboration using the MISP standard format and STIX to support information exchange and interoperability.yeti-platform.io · 9 Oct 2026
Best Yeti alternatives
See all 20 All accessCh 01 Kaspersky Threat Intelligence Portal Free planFree trialAPI Free to start7.4 All accessCh 02 OpenAEV Free planFree trialAPI Free to start7.4 All accessCh 03 IBM X-Force Exchange Free planFree trialAPI Free to start7.3 All accessCh 04 Pulse Intelligence Free planAPILinux Free to start7.3 All accessCh 05 ThreatForge Free planFree trialAPI Free to start7.2 All accessCh 06 Security Vision TIP APILinux 7.0
Where it ranks on Specifiction
Is Yeti yours?
Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.
Sources
- yeti-platform.io· checked 9 Oct 2026
- yeti-platform.io/docs/api/· checked 9 Oct 2026
- yeti-platform.io/docs/getting-started/· checked 9 Oct 2026
- yeti-platform.io/docs/plugins/githubmonitor/· checked 9 Oct 2026
- yeti-platform.io/docs/key-concepts/· checked 9 Oct 2026
- github.com/yeti-platform/yeti· checked 9 Oct 2026
- yeti-platform.io/blog/yeti-misp/· checked 9 Oct 2026
