Colander is a web-based platform for case management, digital investigations, and shared knowledge building. It organizes evidence into cases and supports collaboration among team members and information sharing with other organizations. Its graph editor maps items such as artifacts, actors, observables, and events. Through Threatr, it can retrieve intelligence from VirusTotal, MISP, and OTX AlienVault. Colander can collect and sign artifacts from PiRogue, track their integrity and authenticity, and analyze decrypted network traffic and payloads. Users can decode payloads with CyberChef, apply YARA rules to traffic, generate data transmission reports, and create feeds to export findings. A Python 3 library provides access to its REST API with an API key from the user profile. The project is open source under AGPL v3 and supports Linux, web, API, and self-hosted use. Its deployment guide recommends a dedicated server running the latest Debian version, with at least 4 cores, 4 GB RAM, 500 GB storage, and a public IP address.
Who it is for
Colander is aimed at civil society groups, digital rights defenders, researchers, journalists, and regulatory bodies conducting digital investigations. Its case collaboration and evidence tools may suit teams that need to share findings.
What is good
- Organizes evidence into collaborative cases
- Imports intelligence through Threatr
- Supports traffic analysis, CyberChef, and YARA
- Open source under AGPL v3
What to know first
- Deployment guide recommends a dedicated Debian server
- Recommended minimum storage is 500 GB
- Administrators must encrypt the configuration vault
Verdict
Colander combines case collaboration, evidence handling, threat-intelligence connections, and traffic analysis. Self-hosting requires server resources and careful handling of configuration secrets.
Compared on incident response software
- Case management
- Yes
- Evidence tracking
- Yes
- Responder collaboration
- Yes
- On-call scheduling
- No
- API access
- Yes
- Deployment options
- self_hosted



