Distributed forensics and incident response in the enterprise

Autor: Michael I. Cohen, Germano Caronni, D. Bilby
Rok vydání: 2011
Předmět:
Zdroj: Digital Investigation. 8:S101-S110
ISSN: 1742-2876
DOI: 10.1016/j.diin.2011.05.012
Popis: Remote live forensics has recently been increasingly used in order to facilitate rapid remote access to enterprise machines. We present the GRR Rapid Response Framework (GRR), a new multi-platform, open source tool for enterprise forensic investigations enabling remote raw disk and memory access. GRR is designed to be scalable, opening the door for continuous enterprise wide forensic analysis. This paper describes the architecture used by GRR and illustrates how it is used routinely to expedite enterprise forensic investigations.
Databáze: OpenAIRE