fluggo / investigator

Elasticsearch-based log search and wiki application
GNU General Public License v3.0
2 stars 0 forks source link
active-directory blue-team elasticsearch ldap log-search logging netflow security-tools syslog wiki windows-eventlog

Investigator tools

Elasticsearch-based log search and wiki application. Pairs well with the node-log-forwarder.

This toolset is meant for use by a team for monitoring log activity and changes to inventory, personnel, or other items of interest. The wiki connects to outside sources both to track changes in data as well as to help align multiple data sources, such as Active Directory and a remote agent management system.

As of right now, it has good support for:

Much more can be done to generalize this project and make it applicable to more organizations:

Contact, acknowledgements

Written by Brian Crowell, with special thanks to the organization that supported this project, who has asked to remain anonymous.

This project includes source code from textile.js by Borgar Þorsteinsson and node-windows-sid by Maximilian Haupt.

I consider this an active project, one which I am very happy to return to. If you have an interest or need, please contact me.