All-in-one forensics
Sauron is a forensics ETL (extract - transform - load) that focuses on processing digital forensics artefacts
DFIR-ORC
archives with easeSauron must meet the following requirements:
Install sauron stack
make stack
$ ./bin/sauron --help
Usage: sauron [OPTIONS] COMMAND [ARGS]...
Command-line interface for sauron.
Options:
--version Show the version and exit.
--help Show this message and exit.
Commands:
evtx Parse raw windows event logs.
orc Parse DFIR-ORC files.
./bin/sauron evtx <evtx_folder> --splunk-index evtx_idx
./bin/sauron evtx <evtx_folder> --chainsaw
DFIR-ORC
archive from a given path./bin/sauron orc <orc_folder>
user_hives
and ntfs_info
from a DFIR-ORC
archive./bin/sauron orc <orc_folder> --user_hives --ntfs_info
Usage is provided under the GNU General Public License v3.0. See LICENSE for the full details.