nightHawk Response Logo

nightHawk Response

0
Free
Visit Website

Custom built application for asynchronous forensic data presentation on an Elasticsearch backend, designed to ingest Mandiant Redline 'collections' files, providing flexibility in search, stack, and tagging. The application, accompanied by a fully-fledged GOpher application, allows control over multiple investigations or hundreds of endpoints in a single pane of glass. Version 2.0, ETA March 2020, is under development with features like Docker-based installation, new UI rewrite in React, progressive and resumable triage uploading, Kibana nightHawkResponse Plugin, simplified code base with unit tests, and a simplified development environment CI/CD.

FEATURES

ALTERNATIVES

A powerful reverse engineering framework

Generate comprehensive reports about Windows systems with detailed system, security, networking, and USB information.

Autopsy is a GUI-based digital forensics platform for analyzing hard drives and smart phones, with a plug-in architecture for custom modules.

Hoarder is a tool to collect and parse windows artifacts.

A library and tools to access and manipulate VMware Virtual Disk (VMDK) files.

Recreates the File/Directory tree structure from an extracted $MFT file with detailed record mapping and analysis capabilities.

Review of various MFT parsers used in digital forensics for analyzing NTFS file systems.

A library to access and parse Windows Shortcut File (LNK) format.