Distributed forensics and incident response in the enterprise

M.I. Cohen, D. Bilby, G. Caronni
<span title="">2011</span> <i title="Elsevier BV"> <a target="_blank" rel="noopener" href="https://fatcat.wiki/container/mpetrfjxlffapitphr7jkntyou" style="color: black;">Digital Investigation. The International Journal of Digital Forensics and Incident Response</a> </i> &nbsp;
Remote live forensics has recently been increasingly used in order to facilitate rapid remote access to enterprise machines. We present the GRR Rapid Response Framework (GRR), a new multi-platform, open source tool for enterprise forensic investigations enabling remote raw disk and memory access. GRR is designed to be scalable, opening the door for continuous enterprise wide forensic analysis. This paper describes the architecture used by GRR and illustrates how it is used routinely to expedite enterprise forensic investigations.
<span class="external-identifiers"> <a target="_blank" rel="external noopener noreferrer" href="https://doi.org/10.1016/j.diin.2011.05.012">doi:10.1016/j.diin.2011.05.012</a> <a target="_blank" rel="external noopener" href="https://fatcat.wiki/release/p6uut6dw4bfpvm3qrj7xrduo2m">fatcat:p6uut6dw4bfpvm3qrj7xrduo2m</a> </span>
<a target="_blank" rel="noopener" href="https://web.archive.org/web/20131030014951/http://www.dfrws.org/2011/proceedings/16-348.pdf" title="fulltext PDF download" data-goatcounter-click="serp-fulltext" data-goatcounter-title="serp-fulltext"> <button class="ui simple right pointing dropdown compact black labeled icon button serp-button"> <i class="icon ia-icon"></i> Web Archive [PDF] <div class="menu fulltext-thumbnail"> <img src="https://blobs.fatcat.wiki/thumbnail/pdf/67/ab/67ab443723b641afdc0ff9a7bd7f3f08667f1b1a.180px.jpg" alt="fulltext thumbnail" loading="lazy"> </div> </button> </a> <a target="_blank" rel="external noopener noreferrer" href="https://doi.org/10.1016/j.diin.2011.05.012"> <button class="ui left aligned compact blue labeled icon button serp-button"> <i class="external alternate icon"></i> elsevier.com </button> </a>