Skip to content
#

dfir

Here are 222 public repositories matching this topic...

0xxon
0xxon commented Mar 6, 2020

We should consider mentioning that the single process/standalone mode of Zeek is not suitable for setups with significant amounts of traffic in the quickstart guide at https://docs.zeek.org/en/current/quickstart/index.html.

At the moment is is quite possible to read through this and to not realize that one will have to use a cluster in all settings that see a reasonable amount of traffic.

ProtoDroidBot
ProtoDroidBot commented Jan 20, 2020
  • Operating System Version: Windows 10
  • Provider (VirtualBox/VMWare): Terraform
  • Vagrant Version: N/A
  • Packer Version: N/A
  • Are you using stock boxes (downloaded) or were they built from scratch using Packer? Terraform
  • Is the issue reproducible or intermittent? Attempting to reproduce DetectionLab - Terraform issue #370

Please verify that you are building from an updated Master bran

TheHive
crackytsi
crackytsi commented Mar 3, 2020

Bug / Feature Request

Work Environment

Question Answer
OS version (server) Debian
OS version (client) 10
TheHive version / git hash 4 RC1
Package Type DEB

Problem Description

There are no longer any default dashboards

Possible Solutions

Add the default da

debernal
debernal commented Apr 1, 2019

Hi Florian, I have detected a rule with a false positive, triggering a DDE alert.

Rule: Office_OLE_DDE {

The file, related with iTunes updates, that is triggering the rule is:
http://swcdn.apple.com/content/downloads/56/00/091-97366/e23k1iiixvzrghv5grhee3kss1aqarqexq/AppleMobileDeviceSupport64.msi

File command detects it as:
AppleMobileDeviceSupport64.msi: Composite Document File V2 D

m3047
m3047 commented May 15, 2019

Description

The API doc doc/api.rst doesn't mention the Accept: header.

Environment

Question Answer
Git commit 3e85d9597799e49d6336ba88ac070d4ba05a33ec
OS version n/a
Browser n/a

Expected behavior

It should be documented that the API expects to receive Accept: application/json a

Cortex
ZSZ72
ZSZ72 commented Dec 3, 2019

Work Environment

Question Answer
OS version (server) Ubuntu
OS version (client) 10
Cortex version / git hash Fresh install from DEB
Package Type DEB
Browser type & version Firefox

Problem Description

After updating database in Cortex, when the create adminis

quinnnorton
quinnnorton commented Mar 19, 2019

expand/collapse tree current links to windows, but text controls pop up window. Put text and tree circle on the same horizontal rule, and give them both a similar border, drop the inheritance like from between them. (or possibly from the right hand side of the new border?)

Improve this page

Add a description, image, and links to the dfir topic page so that developers can more easily learn about it.

Curate this topic

Add this topic to your repo

To associate your repository with the dfir topic, visit your repo's landing page and select "manage topics."

Learn more

You can’t perform that action at this time.