End-to-End Digital Forensics & Incident Response Framework
Case Management โข Evidence Processing โข Artifact Parsing โข Timeline Analysis โข Incident Correlation
CyberX DFIR Framework is a modular Digital Forensics and Incident Response (DFIR) platform built using Flask.
The framework provides a unified investigation workspace for:
๐ Case Management
๐ค Evidence Upload & Processing
๐ Artifact Analysis
๐ Timeline Reconstruction
๐จ Incident Detection & Correlation
๐ Investigation Data Export
All forensic artifacts are normalized into a common Event Model, allowing investigators to analyze artifacts across:
- Events Explorer
- Timeline View
- Incident Dashboard
| Artifact | Extensions | Parser / Engine | Output |
|---|---|---|---|
| โ Windows Event Logs | .evtx |
Hayabusa + Sigma Rules | Threat detections, suspicious activities |
| โ Memory Dumps | .raw, .mem, .dmp, .vmem |
Volatility3 + IOC Extraction | Processes, network artifacts, memory analysis |
Evidence Upload
|
โ
Artifact Identification
|
+--------------+--------------+
| | |
EVTX Registry Memory
| | |
Hayabusa Hive Parser Volatility3
| | |
+--------------+--------------+
|
โ
Normalized Event Model
|
+------------+------------+
| |
Timeline Incident Engine
| |
โ โ
Investigation View Threat Detection
git clone https://github.com/itsmeRiF/dfir-framework2.git
cd dfir-framework2python -m venv .venv
.venv\Scripts\activatepip install -r requirements.txtpython bootstrap.pyDownload Hayabusa and place:
hayabusa.exe
inside:
tools/
Before first use:
cd tools
hayabusa.exe update-rulesThis downloads:
- Sigma Detection Rules
- Detection Metadata
- Hayabusa Rule Configuration
python app.pyAccess:
http://127.0.0.1:1338
Default Credentials:
Username: analyst
Password: analyst123
- Windows Event Logs (EVTX)
- Memory Dumps
- Display summary of RAM Analysis
- Running processes
- Active network connections
- Browser History
- Registry Hives
- Prefetch Files
- Jump Lists
- Master File Table (MFT)
- USN Journal
- SRUM Database
- Recycle Bin Analysis
โ
Case Management
โ
Evidence Repository
โ
Artifact Auto Detection
โ
Hayabusa Integration
โ
Sigma Rule Detection
โ
Event Normalization
โ
Timeline Analysis
โ
Incident Correlation
โ
Severity Classification
โ
CSV Export
- MITRE ATT&CK Mapping
- Threat Intelligence Integration
- IOC Extraction Engine
- Automated Investigation Reports
Thanks to all contributors who helped build and test this CyberX DFIR Framework.
Made with โค๏ธ in India ๐ฎ๐ณ
CyberX DFIR Framework