Rastrea2r Logo

Rastrea2r

0
Free
Visit Website

Rastrea2r is a multi-platform open source tool that allows incident responders and SOC analysts to triage suspect systems and hunt for Indicators of Compromise (IOCs) across thousands of endpoints in minutes. It can execute sysinternal, system commands and other 3rd party tools (including custom scripts) across multiple endpoints, saving the output to a centralized share for automated or manual analysis. By using a client/server RESTful API, rastrea2r can also hunt for IOCs on disk and memory across multiple systems using YARA rules. As a command line tool, rastrea2r can be easily integrated within McAfee ePO, as well as other AV consoles and orchestration tools, allowing incident responders and SOC analysts to collect forensic evidence and hunt for IOCs without the need for an additional agent.

FEATURES

ALTERNATIVES

A comprehensive auditd configuration for Linux systems following best practices.

CBRX is a cloud-based platform that automates incident analysis and reporting for cybersecurity teams.

An automation platform with community support and documentation for easy development.

A Security Orchestration, Automation and Response (SOAR) platform for incident response and threat hunting.

npm security team foils plot to steal $13 million in cryptocurrency

A project that uses Athena and EventBridge to investigate API activity and notify of actions for incident response and misconfiguration detection.

Tool to disable vulnerable features in Windows and popular applications for enhanced security.

A mature SIEM environment is critical for successful SOAR implementation.