How this analysis was created: This summary and feature list were written by an AI model that read the project's README and public documentation pages. Each feature links to the documentation it came from; stars, license and language come straight from the GitHub API. The model does not read the source code, and the analysis is refreshed when the project is re-analysed. Learn more on our About page.
Easy-to-use live forensics toolbox for Linux endpoints
The main features of intezer/linux-explorer are: Forensics and Incident Response, Live Forensics and Response, Live Forensics.
Open-source alternatives to intezer/linux-explorer include: mozilla/mig — Distributed & real time digital forensics at the speed of the cloud. google/grr — GRR is a distributed incident response platform and asynchronous forensic task orchestrator. It functions as a remote… tclahr/uac. osquery/osquery — Osquery is a unified endpoint monitoring framework that exposes operating system internals as relational tables. By… velocidex/velociraptor — Velociraptor is a digital forensics and incident response platform, endpoint detection and response system, and… ufrisk/pcileech — pcileech is a toolkit for executing DMA attacks, analyzing PCIe bus traffic, performing kernel patching, and…
Distributed & real time digital forensics at the speed of the cloud
GRR is a distributed incident response platform and asynchronous forensic task orchestrator. It functions as a remote forensics framework designed to collect and analyze volatile data, system memory, and digital artifacts from remote hosts during security incident response. The system operates as a remote endpoint triage system, utilizing a coordinated architecture to manage a fleet of agents. It enables the execution of investigative tasks across multiple systems, allowing for the search of files and registries across a large fleet of machines to identify compromised hosts. The platform pro
Osquery is a unified endpoint monitoring framework that exposes operating system internals as relational tables. By representing hardware, network, and process activity as structured data, it allows users to retrieve system state and configuration information using standard SQL syntax. The system distinguishes itself through a cross-platform abstraction layer that normalizes disparate operating system interfaces into a consistent schema across Windows, macOS, and Linux. It supports both interactive local analysis via a command-line shell and distributed fleet orchestration, where recurring qu