IR tools for the cloud
Let's discuss a few tools that can make IR in the cloud easier for you.
GRR Rapid Response
Developed and maintained by Google, GRR is an open source IR framework for performing live, remote forensic analyses with threat hunting capabilities.
GRR is composed of a server, which issues instructions, and a client, which is deployed on your systems and waits for directions from the server. It's scalable and flexible.
The following screenshot from the tool demonstrates its easy-to-use hunting capabilities:
Figure 5.14: GRR hunting
You can download GRR from GitHub: grr-doc.readthedocs.io.
Malware Information Sharing Platform
Malware Information Sharing Platform (MISP) enables you to collect, store, and share information about cybersecurity threats, indicators, and analyses. It can provide support for SIEMs, network IDSes, and the Linux Intrusion Detection System.
It has a database of incident indicators, an automatic...