{"id":19648145,"url":"https://github.com/bestpractical/rtir","last_synced_at":"2025-04-04T15:08:46.484Z","repository":{"id":45423916,"uuid":"245636","full_name":"bestpractical/rtir","owner":"bestpractical","description":null,"archived":false,"fork":false,"pushed_at":"2024-12-13T19:29:10.000Z","size":8843,"stargazers_count":132,"open_issues_count":1,"forks_count":25,"subscribers_count":35,"default_branch":"5.0-trunk","last_synced_at":"2025-03-28T14:07:37.022Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":"https://bestpractical.com/rtir","language":"Perl","has_issues":false,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"gpl-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/bestpractical.png","metadata":{"files":{"readme":"README.md","changelog":"CHANGES","contributing":null,"funding":null,"license":"COPYING","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":"SECURITY.md","support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2009-07-07T21:52:45.000Z","updated_at":"2025-02-15T16:38:16.000Z","dependencies_parsed_at":"2024-11-11T14:47:28.374Z","dependency_job_id":"6a3be50c-eb2c-4d73-830b-b0e0a72aa8be","html_url":"https://github.com/bestpractical/rtir","commit_stats":null,"previous_names":[],"tags_count":80,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/bestpractical%2Frtir","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/bestpractical%2Frtir/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/bestpractical%2Frtir/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/bestpractical%2Frtir/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/bestpractical","download_url":"https://codeload.github.com/bestpractical/rtir/tar.gz/refs/heads/5.0-trunk","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":247198461,"owners_count":20900080,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-11-11T14:47:16.297Z","updated_at":"2025-04-04T15:08:46.464Z","avatar_url":"https://github.com/bestpractical.png","language":"Perl","funding_links":[],"categories":[],"sub_categories":[],"readme":"\u003cp align=\"center\"\u003e\n  \u003ca href=\"https://bestpractical.com/rtir\"\u003e\n    \u003cimg src=\"https://static.bestpractical.com/rt-ir-logo.png\" alt=\"Best Practical logo\" width=\"500\"\u003e\n  \u003c/a\u003e\n\u003c/p\u003e\n\n\u003ch1 align=\"center\"\u003eRequest Tracker for Incident Response (RTIR)\u003c/h1\u003e\n\n\u003cp align=\"center\"\u003e\n  RT for Incident Response is an open source, industrial-grade\nincident-handling tool designed to provide a simple, effective\nworkflow for members of CERT and CSIRT teams.\n  \u003cbr\u003e\n  \u003ca href=\"https://docs.bestpractical.com/rtir/latest/index.html\"\u003e\u003cstrong\u003eExplore RTIR docs »\u003c/strong\u003e\u003c/a\u003e\n  \u003cbr\u003e\n  \u003cbr\u003e\n  \u003ca href=\"https://docs.bestpractical.com/release-notes/rtir/index.html\"\u003eRelease Notes\u003c/a\u003e\n  ·\n  \u003ca href=\"https://forum.bestpractical.com/\"\u003eCommunity Forum\u003c/a\u003e\n  ·\n  \u003ca href=\"https://rt-wiki.bestpractical.com\"\u003ePublic Wiki\u003c/a\u003e\n  ·\n  \u003ca href=\"https://bestpractical.com/blog/\"\u003eBlog\u003c/a\u003e\n  ·\n  \u003ca href=\"https://bestpractical.com/pricing\"\u003eHosting \u0026 Support\u003c/a\u003e\n  \u003cbr /\u003e\u003cbr /\u003e\n  \u003ca href=\"https://github.com/bestpractical/rtir/releases\"\u003e\n      \u003cimg src=\"https://img.shields.io/github/v/release/bestpractical/rtir\" alt=\"Latest release\" /\u003e\n  \u003c/a\u003e\n  \u003ca href=\"https://github.com/bestpractical/rtir/actions\"\u003e\n      \u003cimg src=\"https://img.shields.io/github/actions/workflow/status/bestpractical/rtir/github-action.yml?branch=5.0-trunk\u0026label=Test%20All\" alt=\"Build status\" /\u003e\n  \u003c/a\u003e\n\u003c/p\u003e\n\u003cp align=\"center\"\u003eIt allows team members\nto track, respond to and deal with reported incidents and features a\nnumber of tools to make common operations quick and easy.  RTIR is\nbuilt on top of \u003ca href=\"https://www.bestpractical.com/rt/\"\u003eRequest Tracker\u003c/a\u003e, which is also available for free from Best\nPractical Solutions.\u003c/p\u003e\n\n![Screenshot of RTIR](docs/images/rtir-incident-dashboard.png)\n\n\u003cp align=\"center\"\u003e\nRT and RTIR are commercially-supported software. To purchase support,\ntraining, custom development, or professional services, please get in\ntouch with us at \u003ca href=\"mailto:mailto:sales@bestpractical.com\"\u003esales@bestpractical.com\u003c/a\u003e.\n\u003c/p\u003e\n\n## REQUIRED PACKAGES\n\n- A compatible version of RT (usually the same version number as RTIR or newer)\n- Net::Whois::RIPE 1.31 is bundled with RTIR for compatibility with the\n  API RTIR uses and for a fix to run without warnings under perl 5.18.\n\n## UPGRADE INSTRUCTIONS\n\nIf you've installed a prior version of RTIR, you will need to follow\nspecial steps to upgrade.  See the [UPGRADING](https://docs.bestpractical.com/rtir/latest/UPGRADING.html) file for detailed\ninformation.\n\n## INSTALLATION INSTRUCTIONS\n\n1. Install the current release of the RT 5.0 series following RT's\nregular installation instructions\n\n2. Run \"perl Makefile.PL\" to generate a makefile for RTIR.\n\n3. Install any extra Perl modules RTIR needs that aren't already\ninstalled. The output from the previous step will list new\nmodules needed, or if existing modules need to be upgraded to a\nnewer version.\n\n4. Type \"make install\".\n\n5. Activate the RTIR extension by putting the following line in your\nRT's etc/RT_SiteConfig.pm file:\n```perl\n  Plugin('RT::IR');\n```\n6. Database:\n\n   A. If you are installing RTIR for the first time, initialize the RTIR\ndatabase by typing \"make initdb\".\n\n   WARNING: Do not attempt to re-initialize the database if you are\nupgrading.\n\n   B. If you are UPGRADING from a previous installation, read the\nUPGRADING file for instructions on how to upgrade your\ndatabase.\n\n1. Stop and start your web server.\n\n\n## CONFIGURING RTIR\n\n1. Using RT's configuration interface, add the email address\nof the Network Operations Team (the people who will handle\nactivating and removing network blocks) as AdminCc on the\nCountermeasures queue.\n   RT -\u003e Queues -\u003e Countermeasures -\u003e Watchers\n\n2. You may want to modify the email messages that are automatically\n   sent on the creation of Investigations and Countermeasures.\n\n   RT -\u003e Queues -\u003e \u003cSelect RTIR's Queue\u003e -\u003e Templates.\n\n   RT -\u003e Global -\u003e Templates.\n\n3. By default, RT ships with a number of global Scrips.  You should use\n   RT's configuration interface to look through them, and disable any\n   that aren't apropriate in your environment.\n\n   RT -\u003e Queues -\u003e \u003cSelect RTIR's Queue\u003e -\u003e Scrips.\n\n   RT -\u003e Global -\u003e Scrips.\n\n4. Add staff members who handle incidents to the DutyTeam group.\n\n   RT -\u003e Configuration -\u003e Groups -\u003e DutyTeam -\u003e Members.\n\n5. You can override values defined in RTIR_Config.pm by creating\n   RTIR_SiteConfig.pm in /opt/rt5/etc/ and adding your customizations.\n\n## SETTING UP THE MAIL GATEWAY\n\nAn alias for the Incident Reports queue will need to be configured.\nAdd the following lines to /etc/aliases (or your local equivalent):\n```\nrtir:         \"|/opt/rt5/bin/rt-mailgate --queue 'Incident Reports' --action correspond --url http://rt.example.com/\"\n```\n\nYou should substitute the URL for RT's web interface for http://rt.example.com/.\n\n-  If your webserver uses SSL, rt-mailgate will require several new\n   Perl libraries. See the RT README for more details on this option.\n\n-  See \"perldoc /opt/rt5/bin/rt-mailgate\" for more info about the rt-mailgate\n   script.\n\n-  If you're configuring RTIR with support for multiple constituencies, please\n   refer to the instructions in the file docs/Constituencies.pod which is also\n   viewable here [http://www.bestpractical.com/docs/rtir/4.0/Constituencies.html](http://www.bestpractical.com/docs/rtir/4.0/Constituencies.html)\n\n## DOCUMENTATION FOR RTIR\n\n- Documents included with RTIR are also available for browsing at\n  [http://www.bestpractical.com/docs/rtir/5.0/](http://www.bestpractical.com/docs/rtir/5.0/)\n\n- This README file\n\n- [UPGRADING documentation](https://docs.bestpractical.com/rtir/5.0/UPGRADING.html)\n\n- There are also version specific upgrading documents available at the\n   [RTIR documentation page](https://docs.bestpractical.com/rtir/5.0/index.html).\n   If upgrading from 3.0, you\n   would read the UPGRADING-3.0, UPGRADING-3.2, UPGRADING-4.0\n   and UPGRADING-5.0 files.\n\n- [RTIR Tutorial](https://docs.bestpractical.com/rtir/5.0/Tutorial.html)\n   - [Extended information about ticket merging](https://docs.bestpractical.com/rtir/5.0/Tutorial.html#Merging-Tickets)\n\n- [Constituencies](https://docs.bestpractical.com/rtir/5.0/Constituencies.html)\n   - Information about setting up RTIR with multiple user constituencies\n\n- [RTIR Administration Tutorial](https://docs.bestpractical.com/rtir/5.0/AdministrationTutorial.html)\n   - Information about setting up RTIR for Administrators\n\n- [RTIR Config](https://docs.bestpractical.com/rtir/5.0/RTIR_Config.html)\n   - Contains a number of RTIR-specific configuration options and\n     instructions for their use\n\n- [RTIR section on our forum](https://forum.bestpractical.com).\n\n## DEVELOPMENT\n\nIf you would like to run RTIR's tests, you need to set a few environment\nvariables:\n\nRT_DBA_USER - a user who can create a database on your RDBMS\n              (such as root on mysql)\nRT_DBA_PASSWORD - the password for RT_DBA_USER\n\nTo run tests:\n\n```sh\n$ RTHOME=/opt/my-rt perl Makefile.PL\n$ RT_DBA_USER=user RT_DBA_PASSWORD=password make test\n```\n\nThese are intended to be run before installing RTIR.\n\nLike RT, RTIR expects to be able to create a new database called rt5test\non your system\n\n## REPORTING BUGS\n\nTo report a bug, send email to [rtir-bugs@bestpractical.com](mailto:rtir-bugs@bestpractical.com).\n\n\n# COPYRIGHT AND LICENSE\n\nCOPYRIGHT:\n\nThis software is Copyright (c) 1996-2024 Best Practical Solutions, LLC\n                                         \u003csales@bestpractical.com\u003e\n\n(Except where explicitly superseded by other copyright notices)\n\n\nLICENSE:\n\nThis work is made available to you under the terms of Version 2 of\nthe GNU General Public License. A copy of that license should have\nbeen provided with this software, but in any event can be snarfed\nfrom www.gnu.org.\n\nThis work is distributed in the hope that it will be useful, but\nWITHOUT ANY WARRANTY; without even the implied warranty of\nMERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU\nGeneral Public License for more details.\n\nYou should have received a copy of the GNU General Public License\nalong with this program; if not, write to the Free Software\nFoundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA\n02110-1301 or visit their web page on the internet at\nhttp://www.gnu.org/licenses/old-licenses/gpl-2.0.html.\n\n\nCONTRIBUTION SUBMISSION POLICY:\n\n(The following paragraph is not intended to limit the rights granted\nto you to modify and distribute this software under the terms of\nthe GNU General Public License and is only of importance to you if\nyou choose to contribute your changes and enhancements to the\ncommunity by submitting them to Best Practical Solutions, LLC.)\n\nBy intentionally submitting any modifications, corrections or\nderivatives to this work, or any other work intended for use with\nRequest Tracker, to Best Practical Solutions, LLC, you confirm that\nyou are the copyright holder for those contributions and you grant\nBest Practical Solutions,  LLC a nonexclusive, worldwide, irrevocable,\nroyalty-free, perpetual, license to use, copy, create derivative\nworks based on those contributions, and sublicense and distribute\nthose contributions and any derivatives thereof.\n\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fbestpractical%2Frtir","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fbestpractical%2Frtir","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fbestpractical%2Frtir/lists"}