-
Updated
Aug 13, 2020 - Shell
dfir
Here are 253 public repositories matching this topic...
-
Updated
Jul 23, 2020
-
Updated
Aug 20, 2020
-
Updated
Aug 26, 2020 - Python
-
Updated
Aug 25, 2020 - HTML
-
Updated
Aug 24, 2020 - XSLT
-
Updated
Aug 26, 2020 - JavaScript
-
Updated
Aug 26, 2020 - Python
-
Updated
Dec 10, 2018 - XSLT
The gist of it is:
Look at url and domain attributes.If url, extract domain and add a domain attribute.Run similarity scorer on the domains using #734 (hides then commonly visited domains)- Do some sort of analysis on the domains... either the ones that are not commonly visited or all of them... ideas would include something like:
- VT or some other domain service l
-
Updated
Aug 8, 2020
-
Updated
Mar 18, 2019 - Go
-
Updated
Aug 25, 2020 - YARA
I was wondering the benefit of using Modular File Management vs Single Config File Management? Why do you consider it easier to use multiple files and then compile? Trying to figure out what the best case is for my use case. Thanks. #
-
Updated
Nov 29, 2017 - Python
-
Updated
Aug 26, 2020 - Python
-
Updated
Dec 3, 2019 - Python
-
Updated
Jul 28, 2020 - Python
-
Updated
Aug 13, 2020 - Scala
-
Updated
Jul 23, 2020
-
Updated
Jul 29, 2020 - Python
-
Updated
Feb 20, 2019 - Batchfile
-
Updated
Jun 17, 2020
Right now a lot of the logging from the tasks does not get propagated back to the user, so we should make sure that all of the tasks are adding logs and errors to the results so that at minimum the data gets put into the worker-log.txt. Ideally we would store this info in datastore so that the clients could query it later (this part is in #115).
-
Updated
Aug 18, 2020 - Python
-
Updated
Aug 26, 2020 - Python
-
Updated
Jul 13, 2018 - Shell
Improve this page
Add a description, image, and links to the dfir topic page so that developers can more easily learn about it.
Add this topic to your repo
To associate your repository with the dfir topic, visit your repo's landing page and select "manage topics."
zeek-cut currently has ability to output "header blocks" in prefix to records. It would be helpful if there was an option that output a simple header row that contained only the corresponding field names, the target format supporting essentially CSV ready output.
Convoluted example of how we're achieving/using today with (for example) the Miller tool to postprocess: