nightHawk Response Logo

nightHawk Response

0
Free
Visit Website

Custom built application for asynchronous forensic data presentation on an Elasticsearch backend, designed to ingest Mandiant Redline 'collections' files, providing flexibility in search, stack, and tagging. The application, accompanied by a fully-fledged GOpher application, allows control over multiple investigations or hundreds of endpoints in a single pane of glass. Version 2.0, ETA March 2020, is under development with features like Docker-based installation, new UI rewrite in React, progressive and resumable triage uploading, Kibana nightHawkResponse Plugin, simplified code base with unit tests, and a simplified development environment CI/CD.

FEATURES

ALTERNATIVES

A digital forensic tool for creating forensic images of computer hard drives and analyzing digital evidence.

Recreates the File/Directory tree structure from an extracted $MFT file with detailed record mapping and analysis capabilities.

A Cross-Platform Forensic Framework for Google Chrome that allows investigation of history, downloads, bookmarks, cookies, and provides a full report.

A collection of Mac OS X and iOS forensics resources with a focus on artifact collection and collaboration.

Python tool for remote memory acquisition

Customizable live OS constructor tool for remote forensics and incident response.

GUI-based memory forensic capture tool for cyber forensics and cyber crime investigation.

Windows event log fast forensics timeline generator and threat hunting tool.

PINNED