Skip to main content

2 posts tagged with "dissect"

View All Tags

Turning DFIR into leads - Part 1

· 7 min read

Incident response investigations often start with a large amount of raw data spread across multiple sources. Forensic images will contain lots of valuable information, but identifying the relevant indicators can easily become overwhelming and time-consuming.

We took a set of playbooks provided by our partner NRD Cyber Security and used them as a starting point to improve our forensics workflows. Our ultimate goal is to turn qcow2 snapshots into investigation leads as easily as possible.

How to configure Dissect for Cowrie snapshots

· 5 min read

Honeypots like Cowrie are a great source of knowledge about attack vectors and new IOCs, but analyzing them can become a cumbersome task - especially because their number can get quite big. That’s where Dissect comes into play. By leveraging its API, you can streamline forensic analysis and automate snapshot processing. This opens up the road to fully automated IOC extraction pipelines that are able to analyze honeypot data and publish threat intelligence to be further processed by IDS tools.

This post is a short guide on how to configure Dissect API to work with Cowrie's snapshots.