GRR Meetup: 3.1.0 Release Apr 2016 Greg Castle @mrgcastle

What we’re releasing Server 3.1.0rc1 Client 3.1.0.0 PyPi today. deb, docker, install scripts etc. coming soon Release notes: goo.gl/a7Z8Hv

What’s new Components: easier client customization Rekall: faster acquisition, more linux profiles Approval ACLs: require different approvals based on client labels

What’s new: continued Powerful API: automatic collection and export Bigquery output plugin: fast analysis at scale Build system: pip install grr-{server|client}

What’s new: continued Lots of bugfixes and perf improvements Hunt UI: OR conditionals Tons more forensic artifacts

Components

Components Bundles of python code Download/update separately from GRR client Delivering Rekall and Chipsec Add your own: blogpost coming soon

Rekall Updateable independently of GRR Good profile coverage of Ubuntu kernels (others coming) AFF4acquire: faster mem acquisition (snappy)

Build system Pip support!* pip install --pre grr-response-server pip install --pre grr-response-client *For now: still some deps required and manual config to use client and server on the same machine

Approval ACLs

Approval ACLs Powerful ACLs to enforce complex approvals E.g. “Machines labelled ‘sensitive’ requires approval from legal and security before access is granted” Blogpost with examples: coming soon

API Covered in previous meetup: goo.gl/8ix5YV Continued to migrate UI functionality to API Enabling externally triggered collection

Bigquery

Bigquery Output Plugin Select Bigquery output for hunts/flows Results streamed as they arrive Fast queries over large result sets See blogpost: goo.gl/vRTxPW

Bigquery Output Plugin

UI: Hunt OR conditionals

Q2 2016 Cloud deployment: gcloud deployment mgr Self-upgrade used at scale Perf: hunt processing, notification Q’s UI: rekall results, hunt UI

Links Release notes: https://github.com/google/grr-doc/blob/master/releasenotes.adoc Bigquery blogpost: http://grr-response.blogspot.com/2015/11/using-bigquery-to-analyze-data.html API meetup slides: https://drive.google.com/a/google. com/file/d/0B1wsLqFoT7i2MEltRFp1Zzk1Rkk/view PyPi packages: https://pypi.python.org/pypi/grr-response-server https://pypi.python.org/pypi/grr-response-client Artifact repo: https://github.com/ForensicArtifacts/artifacts

GRR Meetup- Server-Client Release Apr 2016.pdf

There was a problem previewing this document. Retrying... Download. Connect more apps... Try one of the apps below to open or edit this item. GRR Meetup- ...

362KB Sizes 2 Downloads 185 Views

Recommend Documents

GRR Meetup- API Edition Nov 2015.pdf
There was a problem previewing this document. Retrying... Download. Connect more apps... Try one of the apps below to open or edit this item. GRR Meetup- ...

www.FlamesOfWar.com - Meetup
Jul 14, 2012 - Outpost, demolish bridges with an Engineer Combat Company, ..... Support platoons can be of any variant type and do not have to be from the ...

Boston Clojure Meetup -
“Create truly native iOS apps in Java”. Two things ... http://docs.robovm.com/advanced-topics/bro.html ... libraries, not an abstraction on top of iOS/Android. 3. ... The right tool for native development depends on why you want native in the fir

Sylabs MeetUp -
Feb 22, 2018 - Dial(for higher quality, dial a number based on your current location):. US: +1 408 638 0968 or +1 646 876 9923 or +1 669 900 6833. Meeting ID: 148 587 480. International numbers available: https://zoom.us/zoomconference?m=kOPw3VPmJXA_

Boston Clojure Meetup -
mobile web. ClojureScript. +. X. = hybrid app. Clojure. +. RoboVM (iOS)/ various (Android). = native app. Android's already Java. On. iOS, compile Java bytecode ...

Chef-provisioning-Tokyo-meetup-feb.pdf
Connect more apps... Try one of the apps below to open or edit this item. Chef-provisioning-Tokyo-meetup-feb.pdf. Chef-provisioning-Tokyo-meetup-feb.pdf.

Dan Dietz Greenville Django + Python Meetup - GitHub
Awaken your home: Python and the. Internet of Things. PyCon 2016. • Architecture. • Switch programming. • Automation component. Paulus Schoutsen's talk: ...

Poll "Code4Lib Chicago 2015 Fall Meetup" - Groups
Sep 1, 2015 - November 2015. December 2015. Fri 13. Mon 16. Fri 20. Mon 23. Tue 24. Thu 3. Allan Berry, UIC. OK. OK. OK. OK. OK. OK. Jeremy Prevost ...

Meetup-20160727-SM-Ansible-Rollout.pdf
Loading… Page 1. Whoops! There was a problem loading more pages. Meetup-20160727-SM-Ansible-Rollout.pdf. Meetup-20160727-SM-Ansible-Rollout.pdf.

Meetup-20160727-MK-Ansible-Einfuehrung.pdf
Python 2.6 oder 2.7. •. „managed node“: Unix (auch Windows). – Python 2.5. – Python 2.4 mit python-simplejson. – (libselinux-python). Whoops! There was a ...

Learn Python the Hard Way - Meetup
By going through this book and copying each example exactly, you will be training your brain to ... music theory, ear training, songs, and anything else I can. ...... give to a human. You print them, save them to files, send them to web servers, all

Cloud Security Meetup 30012017.pdf
Loading… Page 1. Whoops! There was a problem loading more pages. Cloud Security Meetup 30012017.pdf. Cloud Security Meetup 30012017.pdf. Open.

20160513-Docker Meetup-uploaded.pdf
Whoops! There was a problem loading more pages. 20160513-Docker Meetup-uploaded.pdf. 20160513-Docker Meetup-uploaded.pdf. Open. Extract. Open with.

VOTO Mobile Director of Programs - Meetup
We also have an API used to power existing mobile service providers. ... University, McKinsey&Company, the Bill & Melinda Gates Foundation, Esoko, Facebook ...

20160513-Docker Meetup-uploaded.pdf
Page 1 of 24. RANCHER & CONTINUOUS DELIVERY. DockerGrunn #6. Johan van der Geest. Edwin Harmsma. Page 1 of 24 ...

VOTO Mobile Director of Programs - Meetup
Bachelors degree required, Master degree preferred. • Experience living and working in your desired country of activity. • Experience of 2+ years in as many of ...

GRR DFRWS US Workshop 2014.pdf
Introduction to GRR. ○ Demo: Setting up your own GRR server. ○ Hands on work. ○ Easy stuff (Files, Registry, ...) ○ More advanced stuff (Investigating live memory). ○ Super interesting stuff (Using Rekall on live memory). ○ Stuff at scale

APR
May 15, 2017 - are also shared during the Guam Early Learning Council quarterly meetings. ... Guam Part C will also post the GRADS360 generated SPP/APR pdf ...... A graphic illustration that shows the rationale of how implementing the ...

Kafka Meetup 18 Oct 2017-1.pdf
Non functional requirements. ○ Provide a near real time data ... Functional requirements. Page 5 of 10. Kafka Meetup 18 Oct 2017-1.pdf. Kafka Meetup 18 Oct ...

SOUTH SHORE MEETUP & GAME NIGHT FORM Spring 2017-pdf.pdf ...
Page 1 of 1. SOUTH SHORE MEETUP & GAME NIGHT FORM Spring 2017-pdf.pdf. SOUTH SHORE MEETUP & GAME NIGHT FORM Spring 2017-pdf.pdf. Open.

expires apr. 30, 2016 - nccdn.net
Page 1. EXPIRES APR. 30, 2016.

Apr Satellite Lunch.pdf
There was a problem previewing this document. Retrying... Download. Connect more apps... Try one of the apps below to open or edit this item. Apr Satellite ...

162, Apr (2017).pdf
Page 2 of 183. The Int. Res. J. Soc. Sc. Hum. . 6 (4) Apr (2017) ISSN 2320 ‐ 4702. ii. THE INTERNATIONAL RESEARCH JOURNAL OF SOCIAL SCIENCES ...

Press Release For Immediate Release
Mar 12, 2013 - financial services technology solutions, today announced that Indiana Auto ... Rankings are tabulated to reflect overall customer service, ...