srum-dump
velociraptor
srum-dump | velociraptor | |
---|---|---|
4 | 5 | |
578 | 2,698 | |
- | 3.7% | |
3.9 | 9.6 | |
6 months ago | 7 days ago | |
Python | Go | |
GNU General Public License v3.0 only | GNU General Public License v3.0 or later |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
srum-dump
- srum-dump: A forensics tool to convert the data in the Windows srum (System Resource Usage Monitor) database to an xlsx spreadsheet - give you the best source of what ran in the last 30 days
-
Custom DFIR
FGET can get the locked files for you. https://github.com/MarkBaggett/srum-dump/blob/master/FGET.exe
- Exfiltration
- Monitor Application Usage without Software Metering
velociraptor
- How to carry out mass Digital Forensic Collections using open source tools?
- List Of Free Web-based OpenSource Tools For Incident Response
-
Custom DFIR
However, what you are trying to do has already been done. For collections look at velociraptor's offline collector https://github.com/Velocidex/velociraptor. For processing check out Log2Timeline (plaso) https://github.com/log2timeline/plaso.
- New blue team
-
We are a security team with 20+ years of ethical hacking, and we've defended over 2 million attacks with Blumira. Ask Us Anything.
https://github.com/Velocidex/velociraptor - purchased recently but still a great tool
What are some alternatives?
plaso - Super timeline all the things
Wazuh - Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
grr - GRR Rapid Response: remote live forensics for incident response
TheHive - TheHive: a Scalable, Open Source and Free Security Incident Response Platform
sigma - Main Sigma Rule Repository
dfirtrack - DFIRTrack - The Incident Response Tracking Application
cariddi - Take a list of domains, crawl urls and scan for endpoints, secrets, api keys, file extensions, tokens and more
auditd - Best Practice Auditd Configuration
Live-Forensicator - Powershell Script to aid Incidence Response and Live Forensics | Bash Script for MacOS Live Forensics and Incidence Response
RedEye - RedEye is a visual analytic tool supporting Red & Blue Team operations
Shuffle - Shuffle: A general purpose security automation platform. Our focus is on collaboration and resource sharing.
dsiem - Security event correlation engine for ELK stack