Johan Berggren
@jberggren
Followers
2K
Following
1K
Media
55
Statuses
885
DFIR @Google :: I write open source tools :: Creator of OpenRelik and Timesketch :: Tweets are my own @[email protected] on Mastodon
Joined August 2010
🚀Introducing OpenRelik: Open-source platform for digital forensic investigations. Modular workflows, collaboration, central artifact repository and easily extendable to support new tools in a clean, easy to use interface. https://t.co/fnkTwtsXDd
openrelik.org
OpenRelik OpenRelik is an open-source (Apache-2.0) platform designed to streamline collaborative digital forensic investigations. It combines modular workflows for custom investigative processes, an...
6
87
229
We’ve released a CLI utility to transform THOR logs into Timesketch-compatible JSONL for timeline analysis Correlate findings across hosts and time, enrich your analysis, and integrate audit-trail logs Supports THOR and THOR Lite 🔗 https://t.co/zEknHKWVXw
0
10
46
We’ve been working on this for a few months - getting the THOR-to-Timesketch integration right meant building not just the CLI tool, but also the pip-installable Python module, proper field mapping logic, and a usable guide. One of the trickier parts was supporting the new
We’ve released a CLI utility to transform THOR logs into Timesketch-compatible JSONL for timeline analysis Correlate findings across hosts and time, enrich your analysis, and integrate audit-trail logs Supports THOR and THOR Lite 🔗 https://t.co/zEknHKWVXw
4
17
77
New #OpenRelik release. Task metrics (queue length, completion, failures etc) & new Prometheus exporter. Plus, a new task dashboard for deep dives into task performance. 📝 https://t.co/VRJS4H2daP 🔗 https://t.co/bz4Pe29CLs
#DFIR
0
2
12
🚀 New OpenRelik release Role-based access control, folder sharing, database improvements, optimisations for file listings, chunked file uploads, bug fixes and refactoring efforts to improve stability. 📝 https://t.co/NAhc3iYvwX 🔗 https://t.co/Rr5G209SnK
#DFIR
discord.com
Check out the OpenRelik community on Discord - hang out with 102 other members and enjoy free voice and text chat.
0
6
7
Great demo of OpenRelik with @eric_capuano and author @jberggren to automate your DFIR workflows for extracting artifacts, processing them with plaso, hayabusa, etc…, and uploading results to Timesketch. https://t.co/48ZsOCXwqV
0
16
66
⚡️ Introducing the OpenRelik Community Discord Server! A dedicated space for technical conversation around the OpenRelik platform. 🔗 Join now to connect, share your ideas and learn from other #DFIR practitioners! https://t.co/LldpycL6Xz
discord.com
Check out the OpenRelik community on Discord - hang out with 102 other members and enjoy free voice and text chat.
0
0
6
Access your #OpenRelik server from your @Tailscale tailnet with this new guide. Tailscale is awesome for simplifying secure network access, and this guide makes it easy to integrate with your existing OpenRelik Docker containers. https://t.co/PydFYoeJry
1
1
15
This week’s Defender Fridays features @jberggren, Staff Security Engineer at @Google. Johan will be discussing OpenRelik - an OSS platform designed for collaborative digital forensic investigations. Join us every Friday: https://t.co/VnoPb37Fvi
#cybersecurity #infosec #dfir
0
1
6
Updated our Hayabusa documentation on support for Sigma correlation rules and updated our aggregation rules to use them: https://t.co/y5f9SsJBge We are also getting close to full support for the Sigma v2 specification! https://t.co/4QVMYAOZN5
1
18
68
Just added Google AI support. Google AI Studio is the frontend for experimentation. It gives you access to Gemini using a simple API key. Very easy to get started. https://t.co/dEU9Dr2L81
0
0
0
OpenRelik now supports local and cloud-based LLMs for developers. Integrate local models (Ollama) or Gemini (VertexAI) into your workers. Easy access to artifacts and extendable with more providers as needed. ✨ What #DFIR capabilities would you build? Share your ideas! 👇
1
1
11
#DFIR Tip of the day: You need to examine IndexedDB or LevelDB? Take a look at this tool from @SydVP
https://t.co/RNOFVgoXPL
github.com
Contribute to google/dfindexeddb development by creating an account on GitHub.
0
2
16
New in #OpenRelik: Artifact Extraction worker! Extract files from disk images using ForensicArtifact definitions and integrate it into your existing workflows. Thanks to Ramses de Beer for the contribution! #forensics #DFIR
3
19
55
Install OpenRelik in under 60 seconds(!) with the improved deployment script (sped-up video for demo). New feature: Local authentication with username/password has been added. No more fiddling with OAuth just to get started.
3
10
66
Introducing our simple Python API client for #OpenRelik. Enjoy seamless authentication and session handling, enabling you to focus on building your applications. pip install openrelik-api-client
0
0
5
This is legit. Might be the easiest DFIR automation workflow tool I've seen yet. Took ~2 minutes to setup with docker compose, and only seconds to generate some Hayabusa outputs. I feel like I am only scratching the surface of what's possible, can't wait to dig in deeper🔥
Two new OpenRelik workers released today: 1. Hayabusa from @SecurityYamato - Analyze your Windows Event Logs. 2. Timesketch exporter - export your timelines seamlessly. #DFIR #OpenRelik 🧵👇See this thread for screencasts:
2
42
205
Another #OpenRelik design proposal just dropped by @hacktobeer! ☁️Cloud Manager - building a seamless integration with cloud disks. Comments welcome! https://t.co/CCo3EfXHx5
openrelik.org
Author: @hacktobeer Published: Sep 2024 Document version: 1.0 Status: Draft ℹ️ Request for comments: If you have questions, comments or suggestions on this design, please share with the community and...
0
2
13
Great talk from Jessica Wilson on open-source #DFIR tools and workflows! - "Forensic Flows, but make them better"
0
4
14
I just published the #OpenRelik design document. It's a high level but pretty detailed description of the system. RFC: Comments, suggestions (and rants) are much appreciated. There is a dedicated discussion forum created, see the doc for the link. https://t.co/5Tgdyc3U1Y
openrelik.org
Author: Johan Berggren Published: Sep 2024 Document version: 1.0 Status: Final ℹ️ Request for comments: If you have questions, comments or suggestions on this design, please share with the community...
0
6
22
2. Timesketch - Export timelines effortless to your Timesketch server. Automatically create sketches from your workflows and get a direct link in OpenRelik for quick access.
1
0
11