awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
google avatar

google/grr

0
View on GitHub↗
5,074 stars·797 forks·Python·Apache-2.0·41 viewsgrr-doc.readthedocs.io↗

Grr

GRR is a distributed incident response platform and asynchronous forensic task orchestrator. It functions as a remote forensics framework designed to collect and analyze volatile data, system memory, and digital artifacts from remote hosts during security incident response.

The system operates as a remote endpoint triage system, utilizing a coordinated architecture to manage a fleet of agents. It enables the execution of investigative tasks across multiple systems, allowing for the search of files and registries across a large fleet of machines to identify compromised hosts.

The platform provides capabilities for digital forensic analysis, including the ability to analyze raw file systems and generate chronological system event timelines. It also includes tools for enterprise fleet monitoring to track resource usage and schedule recurring forensic tasks.

Features

  • Digital Forensics and Incident Response Platforms - Provides a comprehensive platform for hunting indicators of compromise, analyzing disk images, and performing remote triage.
  • Forensic Artifact Collection - Captures specific binaries, memory dumps, and network traffic from remote targets for security investigation.
  • Raw Disk Analysis - Uses forensic toolkits to access OS-level data and recover information directly from physical disks.
  • Endpoint Agent Control - Executes investigative tasks from a central server to manage client agents across a fleet of systems.
  • Forensic Event Timelines - Constructs a chronological sequence of events to reconstruct the activity of an attacker or a specific process.
  • Execution Timeline Reconstruction - Synthesizes disparate forensic artifacts into a chronological history of process executions to reconstruct attacker activity.
  • Direct Underlying Filesystem Accesses - Provides direct access to underlying physical filesystems to recover data independently of the operating system's file APIs.
  • Fleet-Wide File and Registry Search - Locates and downloads specific files or registry keys across a single host or a large fleet of machines.
  • Distributed Task Agents - Utilizes a central controller to dispatch investigative tasks to lightweight agents deployed on remote target hosts.
  • Distributed Artifact Collection - Aggregates volatile memory and file system data from multiple remote targets into a centralized analysis stream.
  • Incident Response Triage - Provides rapid search capabilities for files and registry keys across a large fleet to identify compromised hosts.
  • Remote Endpoint Triage - Provides a centralized server for gathering system memory and forensic evidence from remote targets.
  • Digital Forensics and Analysis - Enables deep-dive investigation of active operating systems through raw file system analysis and event timeline generation.
  • System Forensic Analysis - Collects memory dumps and audit trails to investigate security incidents and analyze attacker interaction with hosts.
  • Forensic Data Aggregators - Aggregates volatile memory and file system data from multiple remote targets into a centralized analysis stream.
  • Distributed Recurring Task Scheduling - Automates the execution of recurring forensic jobs across a distributed fleet using a cron-like schedule.
  • Fleet Security Compliance Monitoring - Tracks resource usage and executes recurring forensic checks across many systems to ensure security compliance.
  • Forensic Task Orchestration - Implements a non-blocking message processing system to schedule and execute forensic jobs across a fleet of targets.
  • Message Queuing Architectures - Implements a message queuing architecture to decouple the scheduling of forensic tasks from their execution across a distributed fleet.
  • Agent Resource Throttling - Monitors and throttles CPU and memory usage on target hosts to prevent forensic activity from impacting production services.
  • System Usage Monitors - Reports real-time device metrics such as CPU and memory usage on target systems to ensure stability during forensics.
  • Forensics and Incident Response - Distributed agent-based forensic and incident response framework.
  • Live Forensics and Response - Remote live forensics framework for incident response.
  • Incident Response Platforms - Framework for remote live forensics using Python agents.
  • Defensive Security - Remote live forensics and incident response capabilities.
  • Digital Forensics - Framework for remote live forensics and incident response.
  • Forensics and Incident Response - Remote live forensics platform for enterprise environments.
  • Hunting Tools - Incident response framework for remote live forensics.
  • Live Forensics - Remote live forensics and incident response platform.
  • Security And Forensics - Remote live forensics and browser-based attack triage.
  • Threat Hunting Operations - Framework for remote live forensics and incident response.
  • Threat Hunting Tools - Remote live forensics and incident response platform.

Star history

Star history chart for google/grrStar history chart for google/grr

How this analysis was created: This summary and feature list are AI-generated from collected project material and can contain mistakes. Stars, license and language are imported from GitHub. Inclusion does not mean that we have tested or audited this project. Check the source documentation for any feature you depend on. Learn more on our About page.

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Start searching with AI

Frequently asked questions

What does google/grr do?

GRR is a distributed incident response platform and asynchronous forensic task orchestrator. It functions as a remote forensics framework designed to collect and analyze volatile data, system memory, and digital artifacts from remote hosts during security incident response.

What are the main features of google/grr?

The main features of google/grr are: Digital Forensics and Incident Response Platforms, Forensic Artifact Collection, Raw Disk Analysis, Endpoint Agent Control, Forensic Event Timelines, Execution Timeline Reconstruction, Direct Underlying Filesystem Accesses, Fleet-Wide File and Registry Search.

Which projects share features with google/grr?

Projects with overlapping indexed features include: velocidex/velociraptor — Velociraptor is a digital forensics and incident response platform, endpoint detection and response system, and… mozilla/mozdef — DEPRECATED - MozDef: Mozilla Enterprise Defense Platform. withsecurelabs/chainsaw — Chainsaw is a Windows forensic analysis tool used for parsing system databases and extracting security artefacts. It… mozilla/mig — Distributed & real time digital forensics at the speed of the cloud. tclahr/uac. neo23x0/loki — Loki is an endpoint detection tool, forensic artifact analyzer, and threat intelligence scanner. It functions as a…

Projects sharing features with Grr

These projects share indexed features with Grr. Shared tags can include platform or build tooling; verify the primary use case before treating a result as a replacement.
  • velocidex/velociraptorVelocidex avatar

    Velocidex/velociraptor

    3,769View on GitHub↗

    Velociraptor is a digital forensics and incident response platform, endpoint detection and response system, and visibility tool. It provides a query engine and remote forensic collector used to hunt for indicators of compromise and perform triage across a fleet of hosts. The system is distinguished by its specialized query language for interrogating host state and parsing binary files. It features a notebook environment that combines markdown documentation with executable query cells to standardize investigative workflows and enable collaborative reporting. The platform covers a wide range o

    Godigital-forensicsendpoint-discoveryendpoint-protection
    View on GitHub↗3,769
  • mozilla/mozdefmozilla avatar

    mozilla/MozDef

    2,164View on GitHub↗

    DEPRECATED - MozDef: Mozilla Enterprise Defense Platform

    Python
    View on GitHub↗2,164
  • withsecurelabs/chainsawWithSecureLabs avatar

    WithSecureLabs/chainsaw

    3,446View on GitHub↗

    Chainsaw is a Windows forensic analysis tool used for parsing system databases and extracting security artefacts. It functions as a forensic artefact extractor and a scanner for identifying security threats and log tampering within Windows event logs. The project distinguishes itself by implementing a Sigma rule forensic scanner that applies standardized detection logic and custom rule sets to event logs and forensic artefacts. It enables threat hunting workflows by matching event data against patterns to identify malicious activity, lateral movement, and brute force attacks. The tool's capa

    Rustattackblueteamchainsaw
    View on GitHub↗3,446
  • tclahr/uactclahr avatar

    tclahr/uac

    1,241View on GitHub↗
    Shellaixcollectorcomputer-forensics
    View on GitHub↗1,241
Compare all 30 related projects→