Distributed & real time digital forensics at the speed of the cloud
GRR is a distributed incident response platform and asynchronous forensic task orchestrator. It functions as a remote forensics framework designed to collect and analyze volatile data, system memory, and digital artifacts from remote hosts during security incident response. The system operates as a remote endpoint triage system, utilizing a coordinated architecture to manage a fleet of agents. It enables the execution of investigative tasks across multiple systems, allowing for the search of files and registries across a large fleet of machines to identify compromised hosts. The platform pro
Osquery is a unified endpoint monitoring framework that exposes operating system internals as relational tables. By representing hardware, network, and process activity as structured data, it allows users to retrieve system state and configuration information using standard SQL syntax. The system distinguishes itself through a cross-platform abstraction layer that normalizes disparate operating system interfaces into a consistent schema across Windows, macOS, and Linux. It supports both interactive local analysis via a command-line shell and distributed fleet orchestration, where recurring qu
Easy-to-use live forensics toolbox for Linux endpoints
Las características principales de intezer/linux-explorer son: Forensics and Incident Response, Live Forensics and Response, Live Forensics.
Las alternativas de código abierto para intezer/linux-explorer incluyen: mozilla/mig — Distributed & real time digital forensics at the speed of the cloud. google/grr — GRR is a distributed incident response platform and asynchronous forensic task orchestrator. It functions as a remote… tclahr/uac. osquery/osquery — Osquery is a unified endpoint monitoring framework that exposes operating system internals as relational tables. By… velocidex/velociraptor — Velociraptor is a digital forensics and incident response platform, endpoint detection and response system, and… ufrisk/pcileech — pcileech is a toolkit for executing DMA attacks, analyzing PCIe bus traffic, performing kernel patching, and…