nightHawk Response Logo

nightHawk Response

0
Free
Visit Website

Custom built application for asynchronous forensic data presentation on an Elasticsearch backend, designed to ingest Mandiant Redline 'collections' files, providing flexibility in search, stack, and tagging. The application, accompanied by a fully-fledged GOpher application, allows control over multiple investigations or hundreds of endpoints in a single pane of glass. Version 2.0, ETA March 2020, is under development with features like Docker-based installation, new UI rewrite in React, progressive and resumable triage uploading, Kibana nightHawkResponse Plugin, simplified code base with unit tests, and a simplified development environment CI/CD.

FEATURES

ALTERNATIVES

Automated Mac Forensic Triage Collector

A library and tools for accessing and analyzing Linux Logical Volume Manager (LVM) volume system format.

A comprehensive Linux log analysis tool that streamlines the investigation of security incidents by extracting and organizing critical details from supported log files.

A toolkit for forensic analysis of network appliances with YARA decoding options and frame extraction capabilities.

A library to access and parse Windows NT Registry File (REGF) format.

A cross-platform registry hive editor for forensic analysis with advanced features like hex viewer and reporting engine.

A Python tool for in-depth PDF analysis and modification.

A software utility with forensic tools for smartphones, offering powerful data extraction and decoding capabilities.

PINNED