google / timesketch

Collaborative forensic timeline analysis
Apache License 2.0
2.62k stars 589 forks source link

Unfurl integration #2897

Closed jkppr closed 1 year ago

jkppr commented 1 year ago

Integrating the dfir-unfurl project into timesketch via the context links. This feature will allow for using unful on every URL in a timesketch url attribute (configurable). Having the unfurl function included in Timesketch allows for easy analysis and understanding of URLs encountered during the investigation.

image

This PR does:

Open tasks:

berggren commented 1 year ago

AHey @jkppr is this still draft or is it ready for review?

jkppr commented 1 year ago

@berggren it is still in draft. There is still some fine tuning around the graph and the setup to be done.

berggren commented 1 year ago

@berggren it is still in draft. There is still some fine tuning around the graph and the setup to be done.

Ack, thanks for the update. Let me know when it is ready for review.

Also, @obsidianforensics for awareness, unfurl is being integrated to TS :)

berggren commented 1 year ago

@obsidianforensics One idea, could we use the official Unfurl logo in the TS UI? That would be nice :)

obsidianforensics commented 1 year ago

Sorry, didn't see the comment until now :/

This is amazing! And yes, please use the official logos wherever you'd like. https://github.com/obsidianforensics/unfurl/tree/main/unfurl/static has a number of different types - I'd probably recommend the square u one rather than the recentagle unfurl one, but feel free to use any.