{"id":51595183,"url":"https://github.com/securityronin/issen","last_synced_at":"2026-07-11T18:01:42.040Z","repository":{"id":367497863,"uuid":"1189146239","full_name":"SecurityRonin/issen","owner":"SecurityRonin","description":"Point it at disk + memory evidence; get a correlated, ATT\u0026CK-mapped attack timeline. Rust DFIR orchestrator: one command ingests E01/EWF/VMDK/raw + memory dumps, parses NTFS/registry/EVTX/prefetch/LNK/SRUM/browser/Amcache + memory (processes, netstat, injection), correlates into a DuckDB super-timeline, scans threat-intel, and reports.","archived":false,"fork":false,"pushed_at":"2026-07-06T16:26:54.000Z","size":77567,"stargazers_count":9,"open_issues_count":1,"forks_count":1,"subscribers_count":0,"default_branch":"main","last_synced_at":"2026-07-06T18:10:20.798Z","etag":null,"topics":["attack-flow","browser-forensics","dfir","digital-forensics","disk-forensics","duckdb","evtx","forensics","incident-response","linux-forensics","memory-forensics","mitre-attack","ntfs","rust","sigma","threat-intelligence","timeline","velociraptor","windows-forensics","yara"],"latest_commit_sha":null,"homepage":null,"language":"Rust","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"other","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/SecurityRonin.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":"CONTRIBUTING.md","funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2026-03-23T02:49:22.000Z","updated_at":"2026-07-06T16:27:55.000Z","dependencies_parsed_at":null,"dependency_job_id":null,"html_url":"https://github.com/SecurityRonin/issen","commit_stats":null,"previous_names":["securityronin/issen"],"tags_count":1,"template":false,"template_full_name":null,"purl":"pkg:github/SecurityRonin/issen","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/SecurityRonin%2Fissen","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/SecurityRonin%2Fissen/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/SecurityRonin%2Fissen/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/SecurityRonin%2Fissen/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/SecurityRonin","download_url":"https://codeload.github.com/SecurityRonin/issen/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/SecurityRonin%2Fissen/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":35370428,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-05-26T15:22:16.424Z","status":"online","status_checked_at":"2026-07-11T02:00:05.354Z","response_time":104,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["attack-flow","browser-forensics","dfir","digital-forensics","disk-forensics","duckdb","evtx","forensics","incident-response","linux-forensics","memory-forensics","mitre-attack","ntfs","rust","sigma","threat-intelligence","timeline","velociraptor","windows-forensics","yara"],"created_at":"2026-07-11T18:01:40.273Z","updated_at":"2026-07-11T18:01:42.034Z","avatar_url":"https://github.com/SecurityRonin.png","language":"Rust","funding_links":["https://github.com/sponsors/h4x0r"],"categories":[],"sub_categories":[],"readme":"\u003cp align=\"center\"\u003e\n  \u003cimg src=\"assets/issen-banner.png#gh-dark-mode-only\"\n       alt=\"Issen — fast forensic triage for incident responders\" width=\"640\" /\u003e\n  \u003cimg src=\"assets/issen-banner-light.png#gh-light-mode-only\"\n       alt=\"Issen — fast forensic triage for incident responders\" width=\"640\" /\u003e\n\u003c/p\u003e\n\n\u003cp align=\"center\"\u003e\n  \u003ca href=\"https://github.com/SecurityRonin/issen/releases\"\u003e\u003cimg src=\"https://img.shields.io/github/v/release/SecurityRonin/issen?style=flat-square\" alt=\"Release\"/\u003e\u003c/a\u003e\n  \u003ca href=\"LICENSE\"\u003e\u003cimg src=\"https://img.shields.io/badge/license-Apache--2.0-blue.svg\" alt=\"License\"/\u003e\u003c/a\u003e\n  \u003ca href=\"https://github.com/SecurityRonin/issen/actions/workflows/ci.yml\"\u003e\u003cimg src=\"https://github.com/SecurityRonin/issen/actions/workflows/ci.yml/badge.svg\" alt=\"CI\"/\u003e\u003c/a\u003e\n  \u003ca href=\"https://www.rust-lang.org\"\u003e\u003cimg src=\"https://img.shields.io/badge/rust-1.80%2B-orange.svg\" alt=\"Rust 1.80+\"/\u003e\u003c/a\u003e\n  \u003ca href=\"#install\"\u003e\u003cimg src=\"https://img.shields.io/badge/platform-Linux%20%7C%20macOS%20%7C%20Windows-blue.svg\" alt=\"Platform\"/\u003e\u003c/a\u003e\n  \u003ca href=\"https://github.com/sponsors/h4x0r\"\u003e\u003cimg src=\"https://img.shields.io/badge/sponsor-h4x0r-ff69b4.svg?logo=github-sponsors\" alt=\"Sponsor\"/\u003e\u003c/a\u003e\n\u003c/p\u003e\n\n**One command turns disk + memory evidence into a correlated, ATT\u0026CK-mapped attack narrative.**\n\nIssen is the orchestration layer of the SecurityRonin forensic fleet — a multi-crate Rust workspace and the `issen` CLI. Hand it acquired evidence, and it auto-detects the container, triages the filesystem for the artifacts that matter, parses each one, and builds a single queryable timeline you can scan and report on.\n\n---\n\n```bash\n# One command: ingest disk artifacts, parse memory dumps, correlate, and scan —\n# in a single resumable pass. Auto-detects E01/EWF/VMDK/raw + memory dumps.\nissen evidence.E01 memory.raw -o case.duckdb\n\n# Read the result: the correlated attack narrative as text (or a shareable HTML report)\nissen report case.duckdb --format text\n```\n\nOne command takes a raw acquisition to a correlated attack narrative. No Python env, no dependency hell — one static binary.\n\n**Resumable by default.** Ingest fingerprints each artifact by content, so re-running re-parses only what changed — a crash, an added source, or a repeated run picks up where it stopped instead of redoing the whole case. An unchanged warm re-ingest drops from **7.36 s to 0.20 s** (~37×): the second pass reads nothing it already has.\n\n---\n\n## How it works\n\nIssen ingests evidence from five independent source types, then correlates across all of them:\n\n\u003ca href=\"https://securityronin.github.io/issen/architecture-diagram.html\"\u003e\n  \u003cimg src=\"assets/architecture.png\"\n       alt=\"Issen architecture diagram — 5 navigation primitives with PARSER, NAVIGATION, CONTAINER, [H] State-History, and KNOWLEDGE layers\"\n       width=\"100%\"/\u003e\n\u003c/a\u003e\n\n*Click the diagram to open the [full interactive version](https://securityronin.github.io/issen/architecture-diagram.html).*\n\n- **Ingests** UAC live response collections, Velociraptor query results, EVTX logs, memory dumps, git repositories, and OCI registries — simultaneously.\n- **Correlates** evidence across all five source types using the Pivot engine: a network connection isn't a finding on its own; combined with a hidden PID, a loaded rootkit library, and a supply-chain hash match, it is.\n- **Outputs** a structured Finding with severity, rule name, and the full evidence chain — ready for your report.\n\nNo Python env. No dependency hell. One static binary.\n\n### The five source types\n\n| ID | Source | Navigation primitive | What it captures |\n|---|---|---|---|\n| **[P]** | Persistent Storage | `name → inode → block` | Disk images (E01/raw), filesystems, file artifacts |\n| **[M]** | Memory | `PID → EPROCESS → VA → PA` | RAM dumps, hiberfil.sys, live-at-time process state |\n| **[L]** | Log | `timestamp → record → field` | EVTX, journal, tracev3, CloudTrail, Zeek/Suricata |\n| **[Q]** | Live Query | `(endpoint, query, cursor) → rows` | Ephemeral state an attacker cannot retroactively destroy |\n| **[C]** | Content-Addressed | `hash → blob → content graph` | Supply chain provenance, Merkle DAG traversal |\n\n**[Q] Live Query** differs fundamentally from the other sources: the data is *produced* by a query rather than *retrieved* from storage. Once captured, the result set is attacker-durable — no subsequent disk wipe changes what `velociraptor collect` saw at query time. The query itself becomes part of the evidence chain.\n\n**[C] Content-Addressed** gives every artifact a globally-unique, tamper-evident identity: its hash. Issen can pivot from a malicious binary hash across git commits, OCI image layers, and Sigstore transparency log entries to answer \"which systems ran this exact blob, when, and where did it come from?\"\n\n---\n\n## Install\n\n```bash\n# Prebuilt binaries — Windows .exe/.msi and Apple-silicon .dmg — on the Releases page:\n#   https://github.com/SecurityRonin/issen/releases\n\n# …or build from source (uses the pinned toolchain in rust-toolchain.toml)\ncargo install --git https://github.com/SecurityRonin/issen issen-cli\n\n# Verify\nissen --version\n```\n\n## The headline workflow\n\n```bash\n# The default pipeline — ingest disk artifacts, parse memory dumps, correlate\n# cross-artifact rules, and scan cached threat-intel feeds. Pass any mix of disk\n# images and memory dumps; re-run the same command to resume where it stopped.\nissen DC01.E01 DESKTOP.E01 DC01-memory.raw -o case.duckdb\n\n# Read the result: correlated findings as text, or a self-contained HTML report\nissen report case.duckdb --format text\nissen report case.duckdb -o report.html\n```\n\nIssen auto-detects each container via its `CollectionProvider` registry, triages the NTFS volume for the artifacts that matter, parses each one, walks memory dumps for process / network / injection state, and correlates everything into one super-timeline. `issen timeline`, `issen report`, and `issen info` all read the same DuckDB database.\n\n### What it triages from a disk image\n\nWhen the evidence is a Windows disk image, Issen walks the NTFS filesystem and extracts:\n\n- **`$MFT`** — the Master File Table (file metadata + timestamps)\n- **`$Extend\\$UsnJrnl:$J`** — the USN change journal (file create/delete/rename history)\n- **All `.evtx`** event logs under `Windows\\System32\\winevt\\Logs` (Security, System, Application, Sysmon, and every other channel)\n- **Registry hives** — `SYSTEM`, `SOFTWARE`, `SAM`, `SECURITY`, `DEFAULT`, plus per-user `NTUSER.DAT`\n- **`SRUDB.dat`** — the System Resource Usage Monitor database\n\n### Fastest evidence formats\n\nIssen reads only the artifacts a triage needs, so it ingests fastest from containers that allow random access **without inflating the whole image**. For the quickest runs:\n\n- ✅ **E01/EWF** — chunk-indexed, so reads stay selective at full compression. The recommended default for acquired evidence.\n- ✅ **raw `.dd`**, or an image stored *uncompressed* inside a **zip** — zero decompression.\n- ✅ **`.bz2` / `.tar.bz2`** — block-seekable; reads decode only the blocks they touch.\n- ✅ **deflate-compressed zip** (e.g. an `.E01.zip` — the shape evidence often ships in) — made seekable by a pure-Rust `zran` DEFLATE index: bounded RAM, decodes only the blocks a triage touches (validated reading an **80 GB** image at **304 MB** peak RSS). Pays a one-pass index build.\n- ⚠️ **`.tar.gz`, `.7z`** — no random-access unit, so Issen must decompress the *entire* image before it can read anything. Fine for transport (e.g. an `.E01.7z`), but extract it to a fast format first.\n\nSee [Selective Decompression for Triage](https://github.com/SecurityRonin/issen/blob/main/docs/selective-decompression-triage.md) for why.\n\n---\n\n## Subcommands\n\n| Command | What it does |\n|---|---|\n| `issen \u003cevidence…\u003e` | **The default pipeline** — ingest disk + memory evidence, correlate, scan, and analyse memory in one resumable pass (`-o` names the case DB) |\n| `issen timeline` | Query and export the timeline (text, JSON, CSV, bodyfile; `--flagged` for findings) |\n| `issen report` | Render the correlated findings as text (`--format text`) or a self-contained HTML report |\n| `issen info` | Show information about a timeline database |\n| `issen memory` | Analyse a physical memory dump (LiME, AVML, Windows crash dump, raw) — processes, netstat, injection, creds |\n| `issen scan` | Scan files or indicators against threat-intel signatures (YARA / Sigma / hash / network) |\n| `issen remote-access` | Scan evidence for remote-access infrastructure (LOLRMM rule set) |\n| `issen rules` | List the bundled detection rules (\"what detections do you have?\") |\n| `issen feed` | Manage threat-intelligence feeds (list, update, inspect) |\n| `issen srum` | Parse and query SRUM (System Resource Usage Monitor) data |\n| `issen biome` | Parse an Apple Biome `App.MenuItem` SEGB file — macOS menu-bar selections |\n| `issen frequency` | Rare-event frequency / stacking analysis across EVTX |\n| `issen processes` | Process-creation events from one or more EVTX files |\n| `issen session` | Correlate Windows logon sessions from EVTX |\n\n```bash\n# Query the timeline; show only flagged findings at high+ severity\nissen timeline timeline.duckdb --flagged --min-severity high\n\n# Export the timeline as CSV or a bodyfile for cross-tool timelining\nissen timeline timeline.duckdb --format csv\nissen timeline timeline.duckdb --format bodyfile\n\n# Analyse a physical memory dump (LiME, AVML, crash dump)\nissen memory dump.lime --command all\n\n# Scan files against YARA / Sigma / hash / STIX signatures\nissen scan evidence/ --auto-feeds\n\n# Update threat-intel feeds (YARA, Sigma, STIX, Zeek, Suricata)\nissen feed update\n```\n\n---\n\n## Trust but verify\n\nIssen has been run end-to-end against a real **29 GB DEF CON E01** acquisition: it auto-detected the container, triaged the NTFS volume, and parsed **843 artifacts** into a **431,863-event** DuckDB timeline. Synthetic fixtures miss real-world quirks; validation against genuine acquired evidence is part of the development discipline.\n\n---\n\n## Fast on real evidence\n\nEngineered to stay bounded at real-world scale — measured, not asserted:\n\n- **Bounded RAM at any size.** Reads an **80 GB** macOS image straight from its deflate-compressed zip (the `zran` DEFLATE index) at **304 MB** peak RSS — RAM doesn't scale with image size.\n- **Resumable by default.** Re-ingesting an unchanged case drops **7.36 s → 0.20 s** (~37×); only changed content re-parses.\n- **Parallel and deterministic.** Evidence sources and their artifacts parse concurrently, and the timeline is byte-identical regardless of which finishes first.\n- **Columnar bulk-load.** Events land through DuckDB's columnar appender, not row-at-a-time inserts — the ingest insert phase runs **~11× faster** (194 s → 17 s).\n\n---\n\n## What it covers\n\n| Category | Formats / Sources |\n|---|---|\n| **Collection formats** | UAC `.tar.gz`, Velociraptor, KAPE triage zip |\n| **Disk images** | E01/EWF, raw DD (split images), VMDK, VHD, VHDX, QCOW2, ISO9660 — auto-detected via a `CollectionProvider` registry |\n| **Filesystems** | NTFS (the Windows disk leg — MFT/USN/hives/$I$R), ext4, APFS [planned] |\n| **Memory formats** | LiME, AVML, WinPMEM, crash dump (DMP), Hibernation (hiberfil.sys) |\n| **Log streams** | EVTX, Zeek `conn.log`, Suricata EVE, systemd journal [planned], Apple Unified Log [planned], CloudTrail [planned] |\n| **Live query** | Velociraptor VQL, WMI/WQL [planned], OSQuery SQL [planned] |\n| **Content-addressed** | git repositories, OCI image registries, IPFS [planned], Sigstore transparency log [planned] |\n| **Detection types** | YARA rules, Sigma rules, STIX 2.1 indicators, hash IOCs, Suricata rules |\n| **Artifact sources** | MFT, USN Journal, EVTX, registry hives (incl. Shimcache / UserAssist / network config), Amcache, Prefetch, LNK / Jump Lists, Recycle Bin ($I/$R content), browser history, SRUM, Apple Biome |\n| **Network analysis** | Volatility sockstat, Zeek logs, Suricata EVE, pcap |\n| **Output formats** | Terminal (colour-coded), JSON, HTML report, PDF, STIX 2.1 Attack Flow, AFB (Attack Flow Builder), DOT/PNG (Graphviz), Mermaid, CSV, bodyfile, DuckDB timeline |\n| **RAT detection** | LOLRMM rule set (400+ tools) |\n| **Attack Flow ingestion** | CTID Attack Flow v3.0.0 corpus — parse STIX bundles → correlation rules via BFS DAG traversal |\n| **Attack Flow output** | STIX 2.1 bundle, `.afb` (Attack Flow Builder), Mermaid `flowchart LR`, PNG (via Graphviz or mmdc) |\n| **VSS awareness** | Enumerates Volume Shadow Copies in evidence trees; `is_vss_path` guard prevents double-counting |\n| **Time-skew detection** | Flags timestamp divergence \u003e 5 min across sources for the same artifact — anti-forensics signal |\n| **Event clustering** | Groups evidence by PID, user, or path for focused correlation queries |\n\n---\n\n## Ecosystem\n\nIssen is the thin correlation layer on top of a family of deep forensic libraries. Each library is independently usable in your own tooling.\n\n| Crate | Source | Layer | Description |\n|---|---|---|---|\n| [forensicnomicon](https://github.com/SecurityRonin/forensicnomicon) | all | Knowledge | Zero-dep compile-time artifact specs, magic bytes, format constants |\n| [state-history-forensic](https://github.com/SecurityRonin/state-history-forensic) | `[H]` | Knowledge | Zero-dep `[H]` functor traits: `HistoricalSource`, `TemporalCohort\u003cH\u003e`, `ClockProvenance`, multi-facet `ArtifactRef` |\n| [ewf](https://github.com/SecurityRonin/ewf) | [P] | Container | E01/EWF → raw sector stream with hash verification |\n| [ext4fs-forensic](https://github.com/SecurityRonin/ext4fs-forensic) | [P] | Filesystem | ext4 sector stream → files by path (name → inode → block) |\n| [4n6mount](https://github.com/SecurityRonin/4n6mount) | [P] | Filesystem | FUSE bridge — makes any container+filesystem pair look like a normal path |\n| [memory-forensic](https://github.com/SecurityRonin/memory-forensic) | [M] | Container + Paging + OS Structure | WinPMEM/LiME/hiberfil → page stream → VA→PA → EPROCESS/VAD/DPAPI |\n| [winevt-forensic](https://github.com/SecurityRonin/winevt-forensic) | [L] | Log Format + Parser | EVTX binary seek + BinXML decode → typed Windows EventRecord |\n| [browser-forensic](https://github.com/SecurityRonin/browser-forensic) | [P][M] | Parser | Chrome/Firefox/Safari history, cookies, downloads, bookmarks, session data |\n| [srum-forensic](https://github.com/SecurityRonin/srum-forensic) | [P][L] | Parser | ESE/JET Blue page walk → SRUM network/process/energy usage records |\n| issen-remote-access | [Q] | Query Engine | Live query dispatcher — Velociraptor VQL, LOLRMM 400+ tool definitions |\n| cas-forensic [planned] | [C] | CAS + Graph | git/OCI/IPFS hash-addressed object store → Merkle DAG navigation |\n| git-forensic [planned] | [C] | Graph + Parser | git commit/blob/tree forensics → supply chain provenance |\n| sigstore-forensic [planned] | [C] | Graph + Parser | Sigstore transparency log entries → artifact signing chain |\n\n\u003cdetails\u003e\n\u003csummary\u003eFull layer hierarchy\u003c/summary\u003e\n\n```\nKNOWLEDGE\n  forensicnomicon        zero-dep, compile-time artifact specs, format constants\n  state-history-forensic zero-dep, [H] functor traits: HistoricalSource,\n                         TemporalCohort\u003cH\u003e, ClockProvenance, ArtifactRef, …\n\nCONTAINER              decode a raw source format → addressable data stream\n  ewf                  E01/EWF → raw sector stream\n  memf-format          memory dumps (WinPMEM, LiME, hiberfil.sys) → raw page stream\n  (log containers are integrated within each log-format crate)\n\nFive parallel paths from CONTAINER — each with its own address space\nand navigation primitive:\n\n[P] Persistent Storage        [M] Memory              [L] Log\n  navigate by: path             navigate by: PID        navigate by: timestamp\n  name → inode → block          PID → EPROCESS          timestamp → record → field\n                                → VA → PA\n\n  FILESYSTEM                    PAGING                  LOG FORMAT\n    ext4fs-forensic               memf-hw                 winevt-forensic (EVTX)\n    ntfs-forensic [planned]       PML4/PAE/AArch64        journal-forensic [planned]\n    apfs-forensic [planned]       OS STRUCTURE            tracev3-forensic [planned]\n    4n6mount (FUSE bridge)          memf-windows            zeek-forensic [planned]\n                                    EPROCESS, VAD           cloudtrail-src [planned]\n                                    DPAPI, DKOM\n                                    memf-linux [planned]\n\n[Q] Live Query                [C] Content-Addressed\n  navigate by: query            navigate by: hash\n  (endpoint, query, cursor)     hash → blob → content graph\n  → result rows\n\n  QUERY ENGINE                  GRAPH NAVIGATION\n    issen-remote-access           cas-forensic\n    velociraptor-parser           git-forensic [planned]\n    WQL / OSQuery [planned]       sigstore-forensic [planned]\n\n[H] State-History (cross-cutting functor — shared traits in state-history-forensic)\n  [P^H] vss-history [planned]            VSS shadow copies, Time Machine, btrfs\n  [P^H] apfs-snapshot-history [planned]  APFS snapshots\n  [M^H] mem-history [planned]            hiberfil chain, VMware memory snapshots\n  [L^H] log-history [planned]            journald sealed epochs, rotated logs\n  [Q^H] query-history [planned]          point-in-time osquery exports\n  [C^H] ≅ [C]                            git already encodes its own history (identity functor)\n\nPARSER                   interpret artifact records → forensic meaning\n  browser-forensic       browser artifact files / SQLite pages → BrowserEvent\n  winevt-forensic        EVTX records → EventRecord\n  srum-forensic          ESE page bytes → SrumRecord\n\nORCHESTRATION\n  Issen            wires all five paths, cross-artifact correlation, CLI\n```\n\n\u003c/details\u003e\n\n---\n\n## Architecture\n\n\u003cdetails\u003e\n\u003csummary\u003eCrate layout\u003c/summary\u003e\n\n```\nissen-cli                   # The issen binary — commands and arg parsing\nissen-core                  # Shared types, plugin traits, error types\nissen-timeline              # DuckDB (primary) + SQLite export timeline store\nissen-fswalker              # Parallel filesystem walk via rayon; SHA-256 integrity; VSS awareness\nissen-unpack                # Collection format detection (UAC tar.gz, Velociraptor, KAPE)\nissen-remote-io             # Remote storage I/O — 48 URI schemes via OpenDAL (S3, GCS, Azure, SFTP, …)\nissen-signatures            # YARA-X, Sigma/Tau-Engine, Hash/Network/STIX/Suricata IOCs, feed sync\nissen-correlation           # Pivot engine: YAML rules, Attack Flow STIX ingestion, zeek-intel, time-skew, clustering\nissen-remote-access         # LOLRMM 400+ tool definitions, RMM/RAT detection; Velociraptor VQL dispatcher\nissen-mem                   # Memory forensics bridge (memf-* sibling workspace)\nissen-report                # HTML/PDF/STIX/AFB/Mermaid/DOT+PNG report generation\nissen-mft-tree              # MFT heuristic analysis\nissen-navigator             # Interactive TUI navigation\nissen-ewf                   # EWF/E01 forensic image support\nissen-evtx                  # Windows Event Log bridge\nparsers/issen-parser-mft    # NTFS MFT + USN Journal parser\nparsers/issen-parser-evtx   # Windows Event Log parser\nparsers/issen-parser-uac    # UAC collection format parser\nparsers/issen-parser-velociraptor  # Velociraptor collection parser\nforensic-pivot              # Sigma/Suricata/STIX rule pivoting\n```\n\nEach crate is independently testable and versioned. The CLI wires them together; you can also use the crates as a library in your own tooling.\n\n\u003c/details\u003e\n\n---\n\n## Correlation Rules\n\nMost tools find indicators. Issen finds **attack patterns** by joining evidence across sources automatically.\n\nA Correlation Rule looks like this:\n\n```yaml\nid: correlation.miner.rootkit-concealment\nseverity: critical\ndescription: Rootkit concealing cryptominer activity via LD_PRELOAD\nwithin_seconds: 300\nreferences:\n  - https://redcanary.com/threat-detection-report/trends/linux-coinminers/\nclauses:\n  - source: artifact\n    required_tag: rootkit_indicator\n  - source: memory\n    required_tag: miner_thread\n  - source: memory\n    required_tag: mining_pool\n```\n\nRules are YAML files in `~/.config/issen/rules/`. Ship your own. Share with your team.\n\nThe bundled rule set ships with rules covering miners, rootkits, SSH tunnels, LD_PRELOAD persistence, hidden processes, and LOLRMM RATs. Custom rules compose with the built-ins — a single `issen \u003cevidence\u003e` pass evaluates all of them.\n\n### Attack Flow STIX ingestion\n\nThe correlation engine also ingests CTID Attack Flow v3.0.0 corpus bundles (STIX 2.1 JSON). Each bundle is parsed into an `AttackFlowBundle` and converted to a `CorrelationRule` via BFS traversal of the `effect_refs` DAG. Every `attack-action` with a `technique_id` becomes a rule clause with `required_tag: \"technique:\u003cID\u003e\"`. The bundled corpus is downloaded with `issen feed update`.\n\n```bash\n# Fetch and index the Attack Flow corpus\nissen feed update\n\n# The engine evaluates Attack Flow rules alongside your YAML rules in the default pass\nissen collection.tar.gz\n```\n\n\u003cdetails\u003e\n\u003csummary\u003eWhy YAML rules and not hard-coded detections?\u003c/summary\u003e\n\nHard-coded detections age badly. Threat actors change port numbers, rename binaries, and swap libraries. YAML rules are versionable, shareable, and reviewable in a pull request. The correlation engine is stable; the rules are data.\n\n\u003c/details\u003e\n\n---\n\n## Demo\n\n```\n$ issen collection-WIN10-CORP-20260401.zip\n\n+===========================================================+\n|  Issen — Collection Analysis                              |\n+===========================================================+\n\n  Collection : collection-WIN10-CORP-20260401.zip\n  Host       : WIN10-CORP\n  OS         : Windows 10 Enterprise 22H2 (19045.4291)\n  Collected  : 2026-04-01T14:32:07Z\n  Artifacts  : MFT, EVTX, Registry, Prefetch, Amcache\n\n  Parsed 1,247,831 MFT entries in 3.2s\n  Parsed 48 EVTX logs (312,406 events) in 1.8s\n  Parsed 4 registry hives in 0.4s\n\n+- PERSISTENCE ───────────────────────────────────────────\n|\n|  [SERVICE] AnyDeskMaint\n|    Binary  : C:\\ProgramData\\Temp\\Support\\anydesk.exe --service\n|    Start   : Auto (SERVICE_AUTO_START)\n|    Account : LocalSystem\n|    Created : 2026-03-28T09:14:22Z\n|\n|  [REG RUN KEY] HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run\n|    Name    : AnyDeskUpdate\n|    Value   : \"C:\\ProgramData\\Temp\\Support\\anydesk.exe\" --start-with-win\n|    Modified: 2026-03-28T09:14:38Z\n\n+- REMOTE ACCESS ─────────────────────────────────────────\n|\n|  [LOLRMM] AnyDesk (relocated binary)\n|    Path    : C:\\ProgramData\\Temp\\Support\\anydesk.exe\n|    SHA256  : a1b2c3d4e5f60718293a4b5c6d7e8f90aabbccdd11223344556677889900eeff\n|    Size    : 5,389,312 bytes\n|    Signed  : philandro Software GmbH (valid, not revoked)\n|    Config  : ad.router.custom_id = \"corp-maint-04\"\n|\n|  [C2 CONNECTION]\n|    Dest IP : 194.36.28.117:7070\n|    First   : 2026-03-28T09:17:03Z\n|    Last    : 2026-04-01T13:58:41Z\n|    Note    : IP not in AnyDesk relay network (AS 208323 / BL Networks, RU)\n\n+- TIMELINE ──────────────────────────────────────────────\n|\n|  2026-03-28T09:12:55Z  [EVTX Security 4624]  Logon Type 3 — CORP\\svc_backup\n|                         from 10.20.5.44 (WIN-RUNBOOK)\n|  2026-03-28T09:14:18Z  [MFT]  File created: C:\\ProgramData\\Temp\\Support\\anydesk.exe\n|                         Parent created at same time — directory is new\n|  2026-03-28T09:14:22Z  [EVTX System 7045]   Service installed: AnyDeskMaint\n|                         ImagePath: C:\\ProgramData\\Temp\\Support\\anydesk.exe --service\n|                         Account: LocalSystem | Type: user mode (0x10)\n|  2026-03-28T09:17:03Z  [EVTX Security 5156] Outbound TCP — anydesk.exe (PID 6284)\n|                         -\u003e 194.36.28.117:7070\n\n+- CORRELATION FINDINGS ──────────────────────────────────\n|\n|  [CRITICAL] LOLRMM with non-vendor C2 infrastructure\n|    Rule    : remote-access.lolrmm.custom-c2\n|    Evidence: AnyDesk outside vendor path (C:\\ProgramData\\Temp\\Support\\)\n|              Outbound -\u003e 194.36.28.117 (AS 208323, not AnyDesk relay ASN)\n|              MFT entry + EVTX 7045 + EVTX 5156 + Registry Run key\n|    MITRE   : T1219, T1543.003\n|\n|  [HIGH] Lateral movement via service account\n|    Rule    : lateral-movement.service-account.file-drop\n|    Evidence: Type 3 logon CORP\\svc_backup from 10.20.5.44 (WIN-RUNBOOK)\n|              File drop + service install within 120s of logon\n|    MITRE   : T1021.002\n\n  2 findings | 1 critical, 1 high | 4 artifact sources correlated\n```\n\nThe correlation engine flagged AnyDesk installed under `C:\\ProgramData\\Temp\\Support\\` — not its standard `Program Files` path — with outbound connections to a Russian ASN outside AnyDesk's relay infrastructure. The timeline shows a service account logon from an internal host, followed by file drop, service install, and first C2 callback within a four-minute window: the attacker pivoted from `WIN-RUNBOOK` using `svc_backup` credentials to deploy the RAT on `WIN10-CORP`.\n\n\n---\n\n## Acknowledgements\n\n**Hal Pomeranz** whose forensic Linux training materials documented ext4 inode/block internals that inform the filesystem layer design.\n\n**Yogesh Khatri** (@SwiftForensics) whose [srum-dump](https://github.com/MarkBaggett/srum-dump) Python tool proved the forensic value of SRUM data and documented the ESE table schemas.\n\n**Jared Atkinson** and the [hayabusa](https://github.com/Yamato-Security/hayabusa) / **Yamato Security** team for pioneering fast, rule-based EVTX triage in Rust and demonstrating the performance ceiling the ecosystem should target.\n\nThe [Volatility Foundation](https://github.com/volatilityfoundation/volatility3) for open-sourcing memory forensics algorithms and kernel structure offsets that inform the memory path design.\n\nThe [Plaso](https://github.com/log2timeline/plaso) / log2timeline team for proving the value of super-timelines and establishing the artifact-to-timeline ingestion model that Issen builds on.\n\n---\n\n[Privacy Policy](https://securityronin.github.io/issen/privacy/) · [Terms of Service](https://securityronin.github.io/issen/terms/) · © 2026 Security Ronin Ltd.\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fsecurityronin%2Fissen","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fsecurityronin%2Fissen","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fsecurityronin%2Fissen/lists"}