01Implementation patterns for automated evidence collection via D&R rules
02Comprehensive evidence collection including files, memory dumps, and MFT data
03Reliable Tasking support for queuing collection commands on offline sensors
04Real-time streaming and historical retrieval of Windows Event Logs and Mac Unified Logs
050 GitHub stars
06Advanced memory analysis tools for process mapping, string extraction, and IOC searching