Tuesday, 25 November 2014

DFRWS EU 2014 - Introduction of Investigation and Intelligence Framework

From the previous post, we provided a workshop about Real Network Security Kungfu in DFRWS EU 2014, in the workshop, we also introduced the concept of Investigation and Intelligence Framework.


The Investigation and Intelligence Framework aims at facilitating the following functions:

  • Import evidence data to our engine, for example Memory Dump, Registry and URLs
  • Our system grabs the data but not limited to IP Addresses, Domains, Emails Addresses.
  • The data grabbed is fed to our  intelligence Engine and give birth of the following information, working out threat forecasting:
    • Timelining
    • Relevance/Confidence Level
    • Activities Correlation


  • The demo is the prototype of Investigation  Intelligence Framework
  • Memory dump is imported, it further digs  out the detected URLs from the IP Address
  • The VirusTotal API finds the one of the IP  Addresses which is suspicious
The Investigation and Intelligence Framework is a on-going research in our team.

No comments:

Post a Comment