Software Engineering Institute | Carnegie Mellon University
Software Engineering Institute | Carnegie Mellon University

Digital Library

Javascript is currently disabled for your browser. For an optimal search experience, please enable javascript.

Advanced Search

Basic Search

Content Type

Topics

Publication Date

Presentation

Minimizing the Gaps with Bro, GRR, and Elk (Brogrrelk)

  • Abstract

    This presentation, given at FloCon 2016, describes a solution that allows incident responders to conduct both host-based triage and network flow/pcap data collections, processes the data, and presents it to an incident responder, all from one platform. GRR collects data from the hosts, Bro captures data from the network, and ELK visualizes the data for incident responders.

  • Download

Part of a Collection

FloCon 2016 Presentations