The premise of this project is to perform live forensics on remote clients using GRR Rapid Response then forward that information to Splunk. The final report will be linked in the References section.
The tools used here are the following:
- Hosted both a list of clients that were to be scanned by GRR and the host machine that will be doing the scanning.
- Ran a network scan on a selected client on GRR.
- Downloaded results as a .csv file format and forwarded to Splunk using email.
- Used Splunk search by host and source to locate file.
- Learned how to scan multiple clients using GRR and what kind of scan to initiate.
- Learned how to determine/select the type of output for the data to be analyzed within GRR.