five

diffy

收藏
DataCite Commons2020-07-30 更新2025-04-09 收录
下载链接:
https://www.impactcybertrust.org/dataset_view?idDataset=1346
下载链接
链接失效反馈
官方服务:
资源简介:
Diffy is a digital forensics and incident response (DFIR) tool developed by Netflix's Security Intelligence and Response Team (SIRT). Diffy allows a forensic investigator to quickly scope a compromise across cloud instances during an incident, and triage those instances for followup actions. "Diffy" helps human investigators identify the differences between instances. Diffy is currently focused on Linux instances running within Amazon Web Services (AWS), but owing to our plugin structure, could support multiple platforms and cloud providers. Diffy is a differencing engine for digital forensics and incident response (DFIR) in the cloud. Collect data across multiple virtual machines and use variations from a baseline, and/or clustering, to scope a incident. Features: - Efficiently highlights outliers in security-relevant instance behavior. For example, you can use Diffy to tell you which of your instances are listening on an unexpected port, are running an unusual process, include a strange crontab entry, or have inserted a surprising kernel module. - Uses one, or both, of two methods to highlight differences: Collection of a "functional" baseline from a "clean" running instance, against which your instance group is compared, and Collection of a "clustered" baseline, in which all instances are surveyed, and outliers are made obvious. - Uses a modular plugin-based architecture. The program includes plugins for collection using osquery via AWS Systems Manager (formerly known as Simple Systems Manager or SSM).
提供机构:
IMPACT
创建时间:
2019-09-10
5,000+
优质数据集
54 个
任务类型
进入经典数据集
二维码
社区交流群

面向社区/商业的数据集话题

二维码
科研交流群

面向高校/科研机构的开源数据集话题

数据驱动未来

携手共赢发展

商业合作