Custom built application for asynchronous forensic data presentation on an Elasticsearch backend, designed to ingest Mandiant Redline 'collections' files, providing flexibility in search, stack, and tagging. The application, accompanied by a fully-fledged GOpher application, allows control over multiple investigations or hundreds of endpoints in a single pane of glass. Version 2.0, ETA March 2020, is under development with features like Docker-based installation, new UI rewrite in React, progressive and resumable triage uploading, Kibana nightHawkResponse Plugin, simplified code base with unit tests, and a simplified development environment CI/CD.
FEATURES
EXPLORE BY TAGS
SIMILAR TOOLS
A digital investigation platform for parsing, searching, and visualizing evidences with advanced analytics capabilities.
MalConfScan is a Volatility plugin for extracting configuration data of known malware and analyzing memory images.
A library and tools to access and manipulate VMware Virtual Disk (VMDK) files.
A binary analysis platform for analyzing binary programs
A digital artifact extraction framework for extracting data from volatile memory (RAM) samples, providing visibility into the runtime state of a system.
WinSearchDBAnalyzer can parse and recover records in Windows.edb, providing detailed insights into various data types.
A library and tools for accessing and analyzing Linux Logical Volume Manager (LVM) volume system format.
PINNED

Mandos
Fractional CISO service that helps B2B companies implement security leadership to win enterprise deals, achieve compliance, and develop strategic security programs.

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.