Johan Berggren Profile
Johan Berggren

@jberggren

Followers
2K
Following
1K
Media
55
Statuses
885

DFIR @Google :: I write open source tools :: Creator of OpenRelik and Timesketch :: Tweets are my own @[email protected] on Mastodon

Joined August 2010
Don't wanna be here? Send us removal request.
@jberggren
Johan Berggren
1 year
🚀Introducing OpenRelik: Open-source platform for digital forensic investigations. Modular workflows, collaboration, central artifact repository and easily extendable to support new tools in a clean, easy to use interface. https://t.co/fnkTwtsXDd
openrelik.org
OpenRelik OpenRelik is an open-source (Apache-2.0) platform designed to streamline collaborative digital forensic investigations. It combines modular workflows for custom investigative processes, an...
6
87
229
@nextronsystems
Nextron Systems
5 months
We’ve released a CLI utility to transform THOR logs into Timesketch-compatible JSONL for timeline analysis Correlate findings across hosts and time, enrich your analysis, and integrate audit-trail logs Supports THOR and THOR Lite 🔗 https://t.co/zEknHKWVXw
0
10
46
@cyb3rops
Florian Roth ⚡️
5 months
We’ve been working on this for a few months - getting the THOR-to-Timesketch integration right meant building not just the CLI tool, but also the pip-installable Python module, proper field mapping logic, and a usable guide. One of the trickier parts was supporting the new
@nextronsystems
Nextron Systems
5 months
We’ve released a CLI utility to transform THOR logs into Timesketch-compatible JSONL for timeline analysis Correlate findings across hosts and time, enrich your analysis, and integrate audit-trail logs Supports THOR and THOR Lite 🔗 https://t.co/zEknHKWVXw
4
17
77
@jberggren
Johan Berggren
11 months
New #OpenRelik release. Task metrics (queue length, completion, failures etc) & new Prometheus exporter. Plus, a new task dashboard for deep dives into task performance. 📝 https://t.co/VRJS4H2daP 🔗 https://t.co/bz4Pe29CLs #DFIR
0
2
12
@jberggren
Johan Berggren
1 year
🚀 New OpenRelik release Role-based access control, folder sharing, database improvements, optimisations for file listings, chunked file uploads, bug fixes and refactoring efforts to improve stability. 📝 https://t.co/NAhc3iYvwX 🔗 https://t.co/Rr5G209SnK #DFIR
discord.com
Check out the OpenRelik community on Discord - hang out with 102 other members and enjoy free voice and text chat.
0
6
7
@SecurityYamato
Yamato Security Tools
1 year
Great demo of OpenRelik with @eric_capuano and author @jberggren to automate your DFIR workflows for extracting artifacts, processing them with plaso, hayabusa, etc…, and uploading results to Timesketch. https://t.co/48ZsOCXwqV
0
16
66
@jberggren
Johan Berggren
1 year
⚡️ Introducing the OpenRelik Community Discord Server! A dedicated space for technical conversation around the OpenRelik platform. 🔗 Join now to connect, share your ideas and learn from other #DFIR practitioners! https://t.co/LldpycL6Xz
discord.com
Check out the OpenRelik community on Discord - hang out with 102 other members and enjoy free voice and text chat.
0
0
6
@jberggren
Johan Berggren
1 year
Access your #OpenRelik server from your @Tailscale tailnet with this new guide. Tailscale is awesome for simplifying secure network access, and this guide makes it easy to integrate with your existing OpenRelik Docker containers. https://t.co/PydFYoeJry
1
1
15
@limacharlieio
LimaCharlie
1 year
This week’s Defender Fridays features @jberggren, Staff Security Engineer at @Google. Johan will be discussing OpenRelik - an OSS platform designed for collaborative digital forensic investigations. Join us every Friday: https://t.co/VnoPb37Fvi #cybersecurity #infosec #dfir
0
1
6
@SecurityYamato
Yamato Security Tools
1 year
Updated our Hayabusa documentation on support for Sigma correlation rules and updated our aggregation rules to use them: https://t.co/y5f9SsJBge We are also getting close to full support for the Sigma v2 specification! https://t.co/4QVMYAOZN5
1
18
68
@jberggren
Johan Berggren
1 year
Just added Google AI support. Google AI Studio is the frontend for experimentation. It gives you access to Gemini using a simple API key. Very easy to get started. https://t.co/dEU9Dr2L81
0
0
0
@jberggren
Johan Berggren
1 year
OpenRelik now supports local and cloud-based LLMs for developers. Integrate local models (Ollama) or Gemini (VertexAI) into your workers. Easy access to artifacts and extendable with more providers as needed. ✨ What #DFIR capabilities would you build? Share your ideas! 👇
1
1
11
@jberggren
Johan Berggren
1 year
#DFIR Tip of the day: You need to examine IndexedDB or LevelDB? Take a look at this tool from @SydVP https://t.co/RNOFVgoXPL
Tweet card summary image
github.com
Contribute to google/dfindexeddb development by creating an account on GitHub.
0
2
16
@jberggren
Johan Berggren
1 year
New in #OpenRelik: Artifact Extraction worker! Extract files from disk images using ForensicArtifact definitions and integrate it into your existing workflows. Thanks to Ramses de Beer for the contribution! #forensics #DFIR
3
19
55
@jberggren
Johan Berggren
1 year
Install OpenRelik in under 60 seconds(!) with the improved deployment script (sped-up video for demo). New feature: Local authentication with username/password has been added. No more fiddling with OAuth just to get started.
3
10
66
@jberggren
Johan Berggren
1 year
Introducing our simple Python API client for #OpenRelik. Enjoy seamless authentication and session handling, enabling you to focus on building your applications. pip install openrelik-api-client
0
0
5
@eric_capuano
Eric Capuano - Bsky: @eric.zip
1 year
This is legit. Might be the easiest DFIR automation workflow tool I've seen yet. Took ~2 minutes to setup with docker compose, and only seconds to generate some Hayabusa outputs. I feel like I am only scratching the surface of what's possible, can't wait to dig in deeper🔥
@jberggren
Johan Berggren
1 year
Two new OpenRelik workers released today: 1. Hayabusa from @SecurityYamato - Analyze your Windows Event Logs. 2. Timesketch exporter - export your timelines seamlessly. #DFIR #OpenRelik 🧵👇See this thread for screencasts:
2
42
205
@jberggren
Johan Berggren
1 year
Great talk from Jessica Wilson on open-source #DFIR tools and workflows! - "Forensic Flows, but make them better"
0
4
14
@jberggren
Johan Berggren
1 year
I just published the #OpenRelik design document. It's a high level but pretty detailed description of the system. RFC: Comments, suggestions (and rants) are much appreciated. There is a dedicated discussion forum created, see the doc for the link. https://t.co/5Tgdyc3U1Y
openrelik.org
Author: Johan Berggren Published: Sep 2024 Document version: 1.0 Status: Final ℹ️ Request for comments: If you have questions, comments or suggestions on this design, please share with the community...
0
6
22
@jberggren
Johan Berggren
1 year
2. Timesketch - Export timelines effortless to your Timesketch server. Automatically create sketches from your workflows and get a direct link in OpenRelik for quick access.
1
0
11