TheHive
dislocker
Our great sponsors
TheHive | dislocker | |
---|---|---|
24 | 26 | |
3,166 | 1,504 | |
2.3% | - | |
0.0 | 2.3 | |
over 1 year ago | 7 months ago | |
Scala | C | |
GNU Affero General Public License v3.0 | GNU General Public License v3.0 only |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
TheHive
-
What are your go-to tools for task management and/or case work?
I had a quick test with the hive looks pretty nice. https://thehive-project.org/
-
Taking Notes: What are your techniques as security professionals?
Also look into hive. Lots of people are moving that direction. https://thehive-project.org/
-
Free Tech Tools and Resources - Connection Tracing, Throttling Tool, Log Search & More
TheHive is a versatile open-source solution for streamlining the investigation and prompt handling of security incidents. Seamlessly integrates with MISP to facilitate the transition from event analysis to investigation initiation, enabling efficient synchronization and export for collaborative threat detection and response. Moreover, coupling TheHive with Cortex empowers security professionals to efficiently analyze up to hundreds of observables. Timely-Lychee-5204 describes it as, "an open-source and scalable Security Incident Response Platform designed for handling incidents efficiently."
-
Monthly Security Checklist
TheHive/Cortex - https://thehive-project.org/
- Does anyone have experience with self-hosted endpoint security solutions?
-
Software for recording security incidents?
i recommend TheHive for creating incident tickets. it is opensource but there is paid one offered by StrangeBee
-
Warning: Do not use Hive Social
Also unrelated to TheHive project, a security incident response tool.
https://thehive-project.org/
- New blue team
- 22 OSINT service for vulnerability detection that can be utilized in IT security.
-
Incident Response: What tool workflow do you use to collaborate on and document IR?
I haven't done any IR myself, but I was thinking something like TheHive Project (open source) or similar proprietary IR toolsets would be common. But over on r/blueteamsec I just saw this post, where people claimed to be using:
dislocker
- Help recover data from old hard drive
-
External USB Disk Encrypted with BitLocker
It seems that there is a project named dislocker that is able to mount bit locker encrypted NTFS partitions. I'm not sure how you would use it on unRAID directly has I don't know which dependency it needs in addition to fuse but you could always try to download the binaries and test it. Otherwise, you can install it easily on any Linux VM if you already got one
-
how are you organizing your data?
Linux can open bitlocker devices, there are tools for that, such as Dislocker, which works on Linux and Mac OS.
-
When i put the correct PIN it says this, how fd up am i?
Even if he does have it, there are tools for linux that can unencrypt the drive if they have the key, which is easy to get from your MS account.
-
What tools do you have on your USB thumbdrive?
You won't be able to access your files unless you use a tool like dislocker and know the password for the bitlocker partition.
-
Windows Hello, Bitlocker and TPM
just a warning to anyone using this tool: it sometimes miscalculated the size of the bitlocker partition when mounting it, which caused my to corrupt my filesystem when trying to modify my windows filesystem size from linux. recompiling with https://github.com/Aorimn/dislocker/pull/252 merged fixed the issue for me
-
Dual Booting Windows 11 (with Bitlocker) and Arch
If you want to access bitlocked files from arch, check out dislocker
-
Dual boot: can both Windows and Linux access the data file?
You should be able to access Windows encrypted drives on Linux using dislocker. It used to work flawlessly last time I needed it, few years ago.
- Bitlocker in Red Hat
-
Best open-source software to clone Windows 10 Bitlocker encrypted machine, safe for company purposes?
There's also an open implementation of Bitlocker that should allow you to mount the image (or disk) on Linux.
What are some alternatives?
Aurora-Incident-Response - Incident Response Documentation made easy. Developed by Incident Responders for Incident Responders
btrfs - WinBtrfs - an open-source btrfs driver for Windows
velociraptor - Digging Deeper....
repo - Arch Linux CN Repository
grr - GRR Rapid Response: remote live forensics for incident response
CyberChef - The Cyber Swiss Army Knife - a web app for encryption, encoding, compression and data analysis
Wazuh - Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
ntfs2btrfs
Kuiper - Digital Forensics Investigation Platform
DidierStevensSuite - Please no pull requests for this repository. Thanks!
catalyst - Catalyst is an open source SOAR and ticket system that helps to automate alert handling and incident response processes
postman-app-support - Postman is an API platform for building and using APIs. Postman simplifies each step of the API lifecycle and streamlines collaboration so you can create better APIs—faster.