Skip to content

About

The automation framework for Digital Forensics and Incident Response --CyberX

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Latest commit

ย 

History

99 Commits

Folders and files

NameName
Last commit message
Last commit date
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 

๐Ÿ›ก๏ธ CyberX | DFIR Framework

End-to-End Digital Forensics & Incident Response Framework

Case Management โ€ข Evidence Processing โ€ข Artifact Parsing โ€ข Timeline Analysis โ€ข Incident Correlation


Python Flask License

Platform Database

Digital Forensics Incident Response Cyber Security Open Source

Last Commit Issues Pull Requests Maintenance Status

Contributions Welcome PRs Welcome

๐Ÿ“Œ Overview

CyberX DFIR Framework is a modular Digital Forensics and Incident Response (DFIR) platform built using Flask.

The framework provides a unified investigation workspace for:

๐Ÿ“ Case Management
๐Ÿ“ค Evidence Upload & Processing
๐Ÿ” Artifact Analysis
๐Ÿ•’ Timeline Reconstruction
๐Ÿšจ Incident Detection & Correlation
๐Ÿ“Š Investigation Data Export

All forensic artifacts are normalized into a common Event Model, allowing investigators to analyze artifacts across:

  • Events Explorer
  • Timeline View
  • Incident Dashboard

๐Ÿ”Ž Artifact Analysis Modules

Artifact Extensions Parser / Engine Output
โœ… Windows Event Logs .evtx Hayabusa + Sigma Rules Threat detections, suspicious activities
โœ… Memory Dumps .raw, .mem, .dmp, .vmem Volatility3 + IOC Extraction Processes, network artifacts, memory analysis

๐Ÿ—๏ธ DFIR Processing Pipeline

                Evidence Upload
                       |
                       โ†“
              Artifact Identification
                       |
        +--------------+--------------+
        |              |              |
      EVTX        Registry       Memory
        |              |              |
    Hayabusa      Hive Parser   Volatility3
        |              |              |
        +--------------+--------------+
                       |
                       โ†“
              Normalized Event Model
                       |
          +------------+------------+
          |                         |
       Timeline              Incident Engine
          |                         |
          โ†“                         โ†“
 Investigation View          Threat Detection

โš™๏ธ Installation

Clone Repository

git clone https://github.com/itsmeRiF/dfir-framework2.git

cd dfir-framework2

Create Virtual Environment

python -m venv .venv

.venv\Scripts\activate

Install Requirements

pip install -r requirements.txt

Create user

python bootstrap.py

Download Hayabusa and place:

hayabusa.exe

inside:

tools/

Before first use:

cd tools

hayabusa.exe update-rules

This downloads:

  • Sigma Detection Rules
  • Detection Metadata
  • Hayabusa Rule Configuration

Start Application

python app.py

Access:

http://127.0.0.1:1338

Default Credentials:

Username: analyst
Password: analyst123

๐Ÿ—บ๏ธ Development Roadmap

Phase 1 โ€” Core Windows Artifacts โœ…

  • Windows Event Logs (EVTX)
  • Memory Dumps

To-do:

  • Display summary of RAM Analysis
  • Running processes
  • Active network connections

Phase 2 โ€” Advanced Artifact Support ๐Ÿšง

  • Browser History
  • Registry Hives
  • Prefetch Files
  • Jump Lists

Phase 3 โ€” File System Forensics ๐Ÿ”ฎ

  • Master File Table (MFT)
  • USN Journal
  • SRUM Database
  • Recycle Bin Analysis

๐Ÿš€ Current Features

โœ… Case Management
โœ… Evidence Repository
โœ… Artifact Auto Detection
โœ… Hayabusa Integration
โœ… Sigma Rule Detection
โœ… Event Normalization
โœ… Timeline Analysis
โœ… Incident Correlation
โœ… Severity Classification
โœ… CSV Export


๐Ÿ”ฎ Future Integrations

  • MITRE ATT&CK Mapping
  • Threat Intelligence Integration
  • IOC Extraction Engine
  • Automated Investigation Reports

๐Ÿ‘ฅ Contributors

Thanks to all contributors who helped build and test this CyberX DFIR Framework.

Made with โค๏ธ in India ๐Ÿ‡ฎ๐Ÿ‡ณ

CyberX DFIR Framework

About

The automation framework for Digital Forensics and Incident Response --CyberX

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages