Acerca de
Streamlines digital forensics and incident response (DFIR) by providing structured guidance for gathering critical evidence from remote endpoints across Windows, macOS, and Linux. It facilitates the collection of volatile data like process memory and network connections, as well as persistent artifacts like event logs and filesystem metadata. By leveraging LimaCharlie's Artifact and Reliable Tasking extensions, it enables automated evidence preservation through Detection & Response rules and ensures collection tasks are successfully executed even on sensors with intermittent connectivity.