Difference between revisions of "GRR"

From ForensicsWiki
Jump to: navigation, search
Line 9: Line 9:
  
 
GRR is an Incident Response Framework focused on Remote Live Forensics.
 
GRR is an Incident Response Framework focused on Remote Live Forensics.
 +
 +
The disk and file system analysis capabilities of GRR are provided by the [[sleuthkit]] and [[pytsk]] projects.
  
 
The memory analysis and acquisition capabilities of GRR are provided by the [[rekall]] project.
 
The memory analysis and acquisition capabilities of GRR are provided by the [[rekall]] project.

Revision as of 15:36, 12 January 2014

Rekall
Maintainer: Darren Bilby and others
OS: Cross-platform
Genre: Incident Response
License: APL
Website: code.google.com/p/grr/

GRR is an Incident Response Framework focused on Remote Live Forensics.

The disk and file system analysis capabilities of GRR are provided by the sleuthkit and pytsk projects.

The memory analysis and acquisition capabilities of GRR are provided by the rekall project.

See also

External Links

Publications

Presentations

Workshops