How this analysis was created: This summary and feature list are AI-generated from collected project material and can contain mistakes. Stars, license and language are imported from GitHub. Inclusion does not mean that we have tested or audited this project. Check the source documentation for any feature you depend on. Learn more on our About page.
GRR is a distributed incident response platform and asynchronous forensic task orchestrator. It functions as a remote forensics framework designed to collect and analyze volatile data, system memory, and digital artifacts from remote hosts during security incident response. The system operates as a remote endpoint triage system, utilizing a coordinated architecture to manage a fleet of agents. It enables the execution of investigative tasks across multiple systems, allowing for the search of files and registries across a large fleet of machines to identify compromised hosts. The platform pro
The security agent that fights back. Watches your Linux server from inside, detects threats with kernel-level eBPF, and stops them with on-device AI. Open-source, self-hosted, dry-run by default. Apache-2.0.
Easy-to-use live forensics toolbox for Linux endpoints
Remote forensics meta tool
The main features of vitaly-kamluk/bitscout are: Disk Imaging Tools, Forensic Distributions, Live Forensics and Response.
Projects with overlapping indexed features include: teamdfir/sift — SIFT. google/grr — GRR is a distributed incident response platform and asynchronous forensic task orchestrator. It functions as a remote… innerwarden/innerwarden — The security agent that fights back. Watches your Linux server from inside, detects threats with kernel-level eBPF,… intezer/linux-explorer — Easy-to-use live forensics toolbox for Linux endpoints. gmagklaras/pofr — Penguin OS Forensic (or Flight) Recorder. osquery/osquery — Osquery is a unified endpoint monitoring framework that exposes operating system internals as relational tables. By…