-
Updated
May 27, 2021 - Shell
dfir
Here are 310 public repositories matching this topic...
-
Updated
Jun 1, 2021
-
Updated
May 19, 2021 - XSLT
-
Updated
Apr 16, 2021
-
Updated
Jun 8, 2021 - HTML
-
Updated
May 22, 2021 - Python
-
Updated
Jun 7, 2021 - Scala
-
Updated
May 26, 2021 - Python
Currently the import client and the backend check for .plaso in the filename to verify it is a plaso file. This is not perfect from user perspective as well as error safe.
Instead the import should check on actual content in the file based on the .plaso format.
-
Updated
May 24, 2021
-
Updated
Dec 10, 2018 - XSLT
I was wondering the benefit of using Modular File Management vs Single Config File Management? Why do you consider it easier to use multiple files and then compile? Trying to figure out what the best case is for my use case. Thanks. #
-
Updated
Apr 22, 2021 - PowerShell
-
Updated
Jun 8, 2021 - YARA
-
Updated
Mar 18, 2019 - Go
-
Updated
May 12, 2021 - Python
-
Updated
Jun 1, 2021 - Python
-
Updated
Nov 29, 2017 - Python
-
Updated
Apr 15, 2021 - Python
-
Updated
Jun 9, 2021
-
Updated
Mar 5, 2021 - Python
-
Updated
Mar 8, 2021 - Shell
-
Updated
May 11, 2021 - Scala
-
Updated
Apr 27, 2021 - Python
-
Updated
Feb 20, 2019 - Batchfile
Right now a lot of the logging from the tasks does not get propagated back to the user, so we should make sure that all of the tasks are adding logs and errors to the results so that at minimum the data gets put into the worker-log.txt. Ideally we would store this info in datastore so that the clients could query it later (this part is in #115).
-
Updated
Feb 3, 2021 - Python
Improve this page
Add a description, image, and links to the dfir topic page so that developers can more easily learn about it.
Add this topic to your repo
To associate your repository with the dfir topic, visit your repo's landing page and select "manage topics."
For consumers of Zeek logs it's handy to have a way to understand the name/goal of the produced logs, what are each log's column names, types, and meaning, etc. Examples of such consumption tasks are