-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathREADME
More file actions
39 lines (23 loc) · 2.05 KB
/
README
File metadata and controls
39 lines (23 loc) · 2.05 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
Linux Forensic Logging Environment
##################################
# Beta: 0.01 #
##################################
Copyright (C) 2014-2020 Georgios Magklaras
Steelcyber Scientific
DISCLAIMER:
-----------
This software is provided AS IS. The author and the hosting institution cannot accept any liabilities for data loss, IT system misconfiguration/interference to normal operation/physical damage or any other lossas a result of running this code.
LFLE Summary
############
The Linux Forensic Logging Environment (LFLE) is a set of tools whose purpose is to provide comprehensive user, process, file access and network endpoint activity data for Linux and Unix based systems. The goal is to provide a tool that can help IT specialists bridge the data loss gap between what post-mortem forensic examination tools can detect and what is lost from the live operation of a system. The collected data is stored away from the monitored systems and thus can shed light on digital forensics investigations of Linux systems that have been security compromised, stolen or physically destroyed.
LFLE is being actively developed by Steelcyber Scientific (https://www.steelcyber.com) and while commercial support is available, the software is Open Source.
The software evolved out of the LUARM logging engine, a research prototype that focused on insider IT misuse mitigation (https://sourceforge.net/projects/luarm/). The architectural limitations (performance, security) of the LUARM v1 research prototype prompted a total redesign of its internals.
Directory structure
===================
-client: Contains code you should install and run on the systems you wish to monitor.
-server: Contains code you should install and run on a dedicated server-grade system that can act as your forensic investigation hub
-doc: Documents you should consult to understand how to install/deploy LFLE, as well as how it works.
Support
=======
Commercial support and bug request queries for LFLE should be directed to:
info@mail.steelcyber.com