Pyflag snort alert log driver plug-in Wiki
pyflag plug-in that makes a snort alert log driver
Brought to you by:
sadeghiafshin
1.Introduction
Digital forensic is described to be as a type of investigation that is using computer generated data as it's source [1]. Network forensics is doing forensic analysis of captured network traffic [2],and disk or memory forensic looks inside the saved bunch of memory data ,This data can be from a part of operating system usage memory running on a computer device to even a part of a movie file stored inside a compressed “tar” file.
The goal of this primary experiment was to make Pyflag to deal with 4 type of log files and make a report of possibilities and limitations of what Pyflag can do with them .This 4 types of log file are:
Snort log files,
Apache log files,
FileZilla log files,
Windows event files.