Giter Club home page Giter Club logo

velociraptor-to-timesketch's Introduction

velociraptor-to-timesketch

sketch

Watch our DFIR Summit talk

Breaches Be Crazy

We will be working on making this a pre-baked AMI, but here are the deployment steps in the meantime <3

Note: You may need to add/modify fs.inotify.max_user_watches in /etc/sysctl.conf. The default is 8192, and you may need to increase this number. Run sysctl -p after modifying.

Deployment

  • Deploy Timesketch instance - Deployment Directions
  • python3/pip3, awscli, unzip, and inotify-tools are required
    apt install python3 python3-pip unzip inotify-tools -y
    pip3 install --upgrade awscli
    
  • Configure AWS CLI
    aws configure 
    
  • Modify bucket_name in watch-s3-to-timesketch.py with S3 bucket name
  • Modify BUCKET_NAME in watch-plaso-to-s3.sh with S3 bucket name
  • Modify $username and $password in watch-to-timesketch.sh
  • Add Velociraptor artifact in Velociraptor and configure with AWS S3 bucket, region, and IAM credentials Screen Shot 2021-07-08 at 2 36 18 PM
  • Run deploy.sh
    ./deploy.sh
    
  • Kick off Windows.KapeFiles.Targets collection on one or more clients in Velociraptor
    • Wait for triage zip to upload to S3
    • Wait for zip to download to Timesketch instance from S3
    • log2timeline will begin processing data into a Plaso file
    • timesketch_importer will then bring it into Timesketch

velociraptor-to-timesketch's People

Contributors

shortstack avatar

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.