- log2timeline / Plaso – timeline generation
- auditd – syscall auditing
- chkrootkit, rkhunter – rootkit scanners
- Volatility, LiME – memory capture
- Zircolite – Sigma rule matching on logs
- CyLR – live response artifact collection
Announcement
Collapse
No announcement yet.
Common Tools for Collection & Analysis
Collapse
X