Remote Live Forensics Using Google GRR Rapid Response
Table of Contents
Introduction
The premise of this project is to perform live forensics on remote clients using GRR Rapid Response then forward that information to Splunk. The final report will be linked in the References section.
Tools Used
The tools used here are the following:
Approach to Problem
- Hosted both a list of clients that were to be scanned by GRR and the host machine that will be doing the scanning.
- Ran a network scan on a selected client on GRR.
- Downloaded results as a .csv file format and forwarded to Splunk using email.
- Used Splunk search by host and source to locate file.
Learning Outcomes
- Learned how to scan multiple clients using GRR and what kind of scan to initiate.
- Learned how to determine/select the type of output for the data to be analyzed within GRR.