Skip to content

Commit

Permalink
Merge branch 'develop' into ld_so_preload
Browse files Browse the repository at this point in the history
  • Loading branch information
tclahr authored Jan 9, 2025
2 parents 8844422 + 057a1b2 commit 29105bb
Show file tree
Hide file tree
Showing 2 changed files with 19 additions and 0 deletions.
4 changes: 4 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -29,6 +29,10 @@
- live_response/system/ulimit.yaml: Added collection of all resource limits information [all] ([mnrkbys](https://github.com/mnrkbys)).
- memory_dump/coredump.yaml: Added collection of core dump, ABRT, Apport, and kdump files [esxi, linux, netbsd] ([mnrkbys](https://github.com/mnrkbys)).

### Profiles

- profiles/offline_ir_triage.yaml: New 'offline_ir_triage' profile that can be used during offline triage collections ([clausing](https://github.com/clausing)).

### New Artifacts Properties

- Added the new 'redirect_stderr_to_stdout' property, an optional feature available exclusively for the command collector. When set to true, this property redirects all error messages (stderr) to standard output (stdout), ensuring they are written to the output file.
Expand Down
15 changes: 15 additions & 0 deletions profiles/offline_ir_triage.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,15 @@
name: offline_ir_triage
description: Offline incident response triage collection.
artifacts:
- bodyfile/bodyfile.yaml
- chkrootkit/chkrootkit.yaml
- hash_executables/hash_executables.yaml
- files/applications/git.yaml
- files/applications/lesshst.yaml
- files/applications/viminfo.yaml
- files/applications/wget.yaml
- files/logs/*
- files/packages/*
- files/shell/*
- files/ssh/*
- files/system/*

0 comments on commit 29105bb

Please sign in to comment.