-
Updated
Jul 31, 2021 - Shell
dfir
Here are 329 public repositories matching this topic...
-
Updated
Jul 26, 2021
-
Updated
Jul 10, 2021 - XSLT
-
Updated
Aug 1, 2021 - HTML
-
Updated
Apr 16, 2021
-
Updated
May 22, 2021 - Python
-
Updated
Jul 31, 2021 - Scala
-
Updated
May 26, 2021 - Python
It would be convenient if deploy_timesketch.sh also started the containers at the end of the run.
-
Updated
Jul 7, 2021
-
Updated
Dec 10, 2018 - XSLT
I was wondering the benefit of using Modular File Management vs Single Config File Management? Why do you consider it easier to use multiple files and then compile? Trying to figure out what the best case is for my use case. Thanks. #
-
Updated
Jun 9, 2021 - PowerShell
-
Updated
Jul 29, 2021 - YARA
-
Updated
Mar 18, 2019 - Go
-
Updated
Aug 2, 2021 - Python
-
Updated
Jun 1, 2021 - Python
-
Updated
Jul 1, 2021
-
Updated
Nov 29, 2017 - Python
-
Updated
Jun 9, 2021 - Python
-
Updated
Mar 5, 2021 - Python
-
Updated
Mar 8, 2021 - Shell
-
Updated
May 11, 2021 - Scala
-
Updated
Apr 27, 2021 - Python
-
Updated
Feb 20, 2019 - Batchfile
Right now a lot of the logging from the tasks does not get propagated back to the user, so we should make sure that all of the tasks are adding logs and errors to the results so that at minimum the data gets put into the worker-log.txt. Ideally we would store this info in datastore so that the clients could query it later (this part is in #115).
-
Updated
Jun 29, 2021 - Python
Improve this page
Add a description, image, and links to the dfir topic page so that developers can more easily learn about it.
Add this topic to your repo
To associate your repository with the dfir topic, visit your repo's landing page and select "manage topics."
Zeek's default base scripts currently disable analyzers, for protocols which support encryption, after the protocol's handshake and once a connection begins using encryption. Module namespaces which do this include
SSL,SSH, andRDP. These namespaces each export a boolean option nameddisable_analyzer_after_detectionwhich controls some logic that wraps a call to the [disable_analyzer](htt