Posts

Showing posts with the label automation

Welcoming OpenRelik to the OSDFIR Infrastructure family

Image
Authored by Johan Berggren and Wajih Yassine Overview If you’ve been keeping a close eye on the OSDFIR Infrastructure repository over the last few months, you might have noticed a new face in the lineup. While many of you have already begun the migration, we are excited (and perhaps a little overdue!) to announce that OpenRelik is available for use through the OSDFIR Infrastructure project! What is OpenRelik? OpenRelik is an open-source platform designed to support collaborative digital forensic investigations. It provides a modular processing pipeline for DFIR teams, combining an interface for workflow management, real-time collaboration features, and a centralized repository for shared artifacts. The platform addresses challenges related to running disparate tools, managing isolated dependencies, and tracking intermediate data across different systems. The primary goal of OpenRelik is to automate the processing of forensic artifacts while using a resilient, distributed architecture...

Welcoming Yeti to the OSDFIR Infrastructure family

Image
Authored by Thomas Chopitea and Wajih Yassine Overview We are excited to announce that Yeti is now available for use through the OSDFIR Infrastructure project.           What is Yeti? Yeti aims to bridge the gap between Cyber Threat Intelligence (CTI) and Digital Forensics & Incident Response (DFIR) practitioners by providing a Forensics Intelligence platform and pipeline for DFIR teams. It was born out of the friction of having to repeatedly answer questions such as “where have I seen this artifact before?”, “how do I search for indicators of compromise (IOCs) related to this (or other) threats in my timeline?”, “what findings have I found useful in similar investigative scenarios?”. The main goal of Yeti is not only to collect IOCs and Techniques, Tactics, and Procedures (TTPs) like a classic threat intelligence platform, but to also store and deliver DFIR intelligence such as useful queries, artifact locations, and methodologies.  How does Yeti...

Introducing OSDFIR Infrastructure: Automating Deployment and Integration of Open Source DFIR Tools to Kubernetes

Image
Overview As digital threats continue to grow, organizations need to be able to respond quickly and effectively to security incidents. One critical component of incident response is having the right set of tools at hand to analyze and respond to threats. However, manually deploying and integrating multiple open source DFIR tools can be a time-consuming and error-prone process, causing significant delays in incident response times, which can lead to a higher risk of damage to the organization. To address this challenge, we are excited to share an open source repository for deploying and managing Open Source Digital Forensics & Incident Response (OSDFIR) tools in Kubernetes . OSDFIR Infrastructure automates the tedious deployment and configuration steps, removing the manual labor involved in setting up and maintaining an enterprise DFIR Infrastructure in Kubernetes.  Using this has helped save hours of time by reducing the time required to deploy, configure, and maintain each too...