-
Notifications
You must be signed in to change notification settings - Fork 521
GRR
From: https://github.com/google/grr
GRR Rapid Response: remote live forensics for incident response
We can add GRR to Security Onion as a Docker container to enhance its current capabilities and leverage the great work from the folks at Google.
Please keep in mind we do not officially support GRR, so installation is at your own risk.
To install GRR on Security Onion:
Get the install script:
sudo wget https://raw.githubusercontent.com/weslambert/securityonion-grr/master/install_grr
Make the script executable :
sudo chmod +x install-grr
Run the script:
sudo ./install_grr
Follow the prompts, and once finished, you should be able to navigate to GRR via https://domain.you.specified
.
(Note this address in also referenced in /etc/apache2/sites-available/grr.conf
.
Keep in mind, GRR is still accessible at http://localhost:8000
, so you will want to make sure only port 443 is allowed externally, or alter your web server settings appropriately.
If you would like to add another user, aside from the default, you can follow the instructions here:
https://github.com/google/grr-doc/blob/master/admin.adoc#user-management
For more information on the GRR Docker image, see here:
https://github.com/google/grr-doc/blob/master/docker.adoc
- Introduction
- Use Cases
- Hardware Requirements
- Release Notes
- Download/Install
- Booting Issues
- After Installation
- UTC and Time Zones
- Services
- VirtualBox Walkthrough
- VMWare Walkthrough
- Videos
- Architecture
- Cheat Sheet
- Conference
- Elastic Stack
- Elastic Architecture
- Elasticsearch
- Logstash
- Kibana
- ElastAlert
- Curator
- FreqServer
- DomainStats
- Docker
- Redis
- Data Fields
- Beats
- Pre-Releases
- ELSA to Elastic
- Network Configuration
- Proxy Configuration
- Firewall/Hardening
- Email Configuration
- Integrating with other systems
- Changing IP Addresses
- NTP
- Managing Alerts
- Managing Rules
- Adding Local Rules
- Disabling Processes
- Filtering with BPF
- Adjusting PF_RING for traffic
- MySQL Tuning
- Adding a new disk
- High Performance Tuning
- Trimming PCAPs