got to present my recent experience with #openrelik, #hayabusa, #timesketch and #splunk4dfir to my team. Took the entire afternoon but psyched about integrating them into company workflows π₯
tested #openrelik, #hayabusa, #timesketch and #splunk4dfir using #thedfirreport recent analyst case. was a lot fun! will definitely use those tools more now π
Hey #DFIR people! New #OpenRelik release just dropped. Some cool new features and a bunch of bug fixes.
New #OpenRelik release 0.5.0 is here with some cool new additions:
* Import files directly from Google Cloud Storage
* Updated AI summary visuals
* Glob filtering support when extracting archives
* BlockDevice support for mounting disk images and partitions
Changelog: openrelik.org/changelog/#050
Great stuff from @tomchop.me! Memory analysis and Yara support in #OpenRelik
#DFIR
Demo of the Volatility 3 worker extracting files and plugin output
Demo of the Yara scanner worker showing matches for a dumb DarkComet rule
I had a look at #OpenRelik last year and wrote a couple workers that might be useful:
* github.com/tomchop/open...: Scan memory images using @volatilityfoundation.org plugins. Supports Yara rules
* github.com/tomchop/open... - Run Yara rules on a directory. Supports third-party systems like #Yeti!
New #OpenRelik release. Task metrics (queue length, completion, failures etc) & new Prometheus exporter. Plus, a new task dashboard for deep dives into task performance.
π openrelik.org/changelog/
π discord.gg/hg652gktwX
#DFIR
Access your #OpenRelik server from your @tailscale.com tailnet with this new guide. Tailscale is awesome for simplifying secure network access, and this guide makes it easy to integrate with your existing OpenRelik Docker containers.