
Easy-to-use live forensics toolbox for Linux endpoints with various capabilities such as process inspection, memory analysis, and YARA scanning.

Easy-to-use live forensics toolbox for Linux endpoints with various capabilities such as process inspection, memory analysis, and YARA scanning.
Linux Expl0rer is a Detection Engineering product. Pricing is free.
Easy-to-use live forensics toolbox for Linux endpoints written in Python & Flask. Capabilities: - View full process list - Inspect process memory map & fetch memory strings easily - Dump process memory in one click - Automatically search hash in public services (VirusTotal, Intezer, Analyze AlienVault OTX, MalShare) - Users list find - Search for suspicious files by name/regex - netstat - Whois - Logs: syslog, auth.log (user authentication log), ufw.log (firewall log), bash history - Anti-rootkit chkrootkit - YARA: Scan a file or directory using YARA signatures by @Neo23x0, Scan a running process memory address space, Upload your own YARA signature Requirements: Python 3.6 Installation: - wget https://github.com/intezer/linux-explorer/archive/master.zip -O master.zip - unzip master.zip - cd linux-explorer-master - ./deploy.sh Usage: Start your browser firefox http://127.0.0.1:8080 Configure API keys (optional): - nano config.py - Edit following lines: INTEZER_APIKEY = '<key>', VT_APIKEY = '<key>', OTX_APIKEY = '<key>', MALSHARE_APIKEY = '<key>' Notes: We recommend using NGINX reverse proxy with basic http auth & ssl for secure remote access. Tested with Ubuntu 16.04 Misc: "How to"
Common questions about Linux Expl0rer including features, pricing, alternatives, and user reviews.
Linux Expl0rer is Easy-to-use live forensics toolbox for Linux endpoints with various capabilities such as process inspection, memory analysis, and YARA scanning. It is a Security Operations solution designed to help security teams with Linux, Memory Forensics.
Linux Expl0rer is built for security teams handling Linux, Memory Forensics. Teams typically adopt Linux Expl0rer when they need to security operations capabilities integrated into their existing stack. Explore similar tools at https://cybersectools.com/alternatives/linux-expl0rer
Linux Expl0rer is a free Security Operations tool. This makes it accessible for organizations of all sizes, from startups to enterprises. Visit https://github.com/intezer/linux-explorer/ for download and installation instructions.
Popular alternatives to Linux Expl0rer include:
Compare all Linux Expl0rer alternatives at https://cybersectools.com/alternatives/linux-expl0rer
Linux Expl0rer is for security teams and organizations that need Linux, Memory Forensics. It's particularly suitable for small to medium-sized teams looking for cost-effective solutions. Other Security Operations tools can be found at https://cybersectools.com/categories/security-operations
Head-to-head feature, pricing, and rating breakdowns.
OCyara performs OCR on images and PDF files to extract text content and scan it against Yara rules for malware detection.
A comprehensive auditd configuration for Linux systems following best practices.
An OCaml Ctypes wrapper for the YARA matching engine that enables malware identification capabilities in OCaml applications.
A collection of YARA rules specifically designed for forensic investigations and malware analysis, providing pattern matching capabilities for files and memory dumps.