{"repo":"SecurityRonin/issen","free":true,"listed":false,"github":"https://github.com/SecurityRonin/issen","clone":"git clone https://github.com/SecurityRonin/issen.git","description":"Point it at disk + memory evidence; get a correlated, ATT&CK-mapped attack timeline. Rust DFIR orchestrator: one command ingests E01/EWF/VMDK/raw + memory dumps, parses NTFS/registry/EVTX/prefetch/LNK/SRUM/browser/Amcache + memory (processes, netstat, injection), correlates into a DuckDB super-timeline, scans threat-intel, and reports.","language":"Rust","stars":10,"topics":["dfir","digital-forensics","forensics","incident-response","rust","sigma","threat-intelligence","timeline","yara","memory-forensics"],"license":"Apache-2.0","category":"deployment-docker-iac","readme_excerpt":"The image is on your desk. The clock is running. Point Issen at it — read the attack story. You have an acquisition and no time. Issen takes it from raw evidence to a correlated, ATT&CK-mapped attack narrative in one command — no Python env, no dependency hell, no config, nothing to set up. One static binary. It auto-detects the container (E01/EWF/VMDK/raw), triages the filesystem for the artifacts that matter, walks the memory dump for process / network / injection state, and correlates disk + memory + logs into one timeline — then hands you the findings, ranked by severity, each with its full evidence chain. You don't write a query. --- What one command hands back A real run — an AnyDesk RAT dropped through a service-account pivot, found and MITRE-mapped without a single query written: Most tools hand you indicators and let you connect them. Issen joins the evidence across sources — a network connection is not a finding on its own; combined with a relocated RMM binary, a service install, and a logon from an internal host, it is the attack. That is the whole point: it finds the pattern , not just the pieces. --- Install Two minutes to your first timeline Resumable by default — a long case is never lost. Ingest fingerprints each artifact by content, so re-running only re-parses what changed. A crash, an added source, or a repeat run picks up where it stopped instead of redoing the case: an unchanged warm re-ingest drops from 7.36 s → 0.20 s ( 37×). --- The commands you'll act","default_branch":null,"files":null,"tree":[],"storefront":"/r/SecurityRonin","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/SecurityRonin/issen/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}