LogoLogo
CtrlK
Back to binalyze.com
  • AIR Knowledge Base
  • AIR Platform
    • AIR
      • What is AIR?
      • Terminology
      • Architecture
        • AIR Responder Architecture; overview and performance analysis
        • AIR Task Flow and Management
      • Network Communication
      • Cloud Forensics
    • Setup
      • Relay Server
        • What is Relay Server?
        • Requirements for installation
        • How to install a Relay Server on different Linux platforms
        • How to change IP address of Relay Server
        • How to install a Responder with Relay Server support
        • Proxy configurations
          • Adding proxy to Relay Server
        • Service Management for Relay Server
        • Whitelisting for Relay Server
        • Retrieving metrics from Relay Server
        • Updating and Uninstalling Relay Server
        • Troubleshooting
      • Responder
        • Responder Hardware Requirements
        • Responder - Supported Operating Systems
          • Responder - MS Windows supported systems
          • Responder - Apple macOS supported systems
          • Responder - Linux (DEB/RPM) supported systems
          • ESXi Standalone Collector
          • Responder - Chrome supported systems
            • AIR For Chrome
        • Responder for Golden Images
        • Responder and Active Directory OUs
        • Responder Exception Rules
          • AIR Watchdog Folder
        • FDA via Jamf and Apple's PPPC utility
        • Responder in Windows Safe Mode
      • Security
        • Two-factor authentication (2FA)
    • Settings
      • Console Settings
        • General
        • Assets
        • Security
        • Features
        • Evidence Repositories
        • Policies
        • User Management
          • User Groups
          • User Roles
        • Backup
        • Investigation Hub Disk Usage
        • Danger Zone
      • Organization Settings
      • Account Settings
    • Updating
      • Console Updating - SaaS
    • Features
      • Acquisition
        • Task Creation
          • Regex in DRONE:
          • Asset Management with Persistent Saved Filters
          • Task Cancellation and Deletion
        • Acquisition Profiles
        • Supported Evidence
          • Windows Collections
          • macOS Collections
          • Linux Collections
          • IBM AIX Collections
        • Scheduling Tasks
        • Disk and Volume Imaging
          • Imaging with interACT
        • Chain Of Custody
      • Auto Tagging & Tags
        • Tags
      • Triage
        • Triage Rule Templates
          • YARA Templates
          • Sigma Templates
          • osquery Templates
        • Schedule Triage Tasks
      • interACT
        • interACT Commands
        • PowerShell commands in interACT
      • Compare
      • Timeline
      • Integrations
        • Microsoft Azure Cloud Platform Integration
        • SSO Integrations
          • Microsoft Azure SSO Integration
          • Okta SAML 2.0 SSO Integration
          • FortiAuthenticator SAML 2.0 SSO Integration
        • Webhooks
          • Mattermost Integration
          • Splunk Integration
          • IBM QRadar Integration
          • Wazuh Integration
          • Cortex XSOAR Integration
          • Elasticsearch Logstash Kibana Integration
          • ServiceNow Integration
          • Sumo Logic Integration
          • Crowdstrike Integration
          • Microsoft Sentinel Integration
          • Slack Integration
          • Carbon Black Cloud Integration
          • Rapid7 InsightIDR Integration
          • LogicHub SOAR (DEVO) Integration
          • Fortigate SIEM Integration
          • Dynatrace Integration
          • Stellar XDR Integration
          • SentinelOne Integration
          • Microsoft 365 Defender Integration
          • Cisco XDR Integration
      • Event Subscription
      • API
        • API is likely to be more effective than Webhooks
      • DRONE
        • What is DRONE?
        • What is an Analysis Pipeline?
        • Analyzers
          • Cross Platform Analyzers
            • MITRE ATT&CK Analyzer
              • MITRE ATT&CK Analyzer changelog
            • Dynamo Analyzer
            • Browser History Analyzer
            • Generic WebShell Analyzer
          • Windows Analyzers
            • Windows Event Records and how they are handled
              • Windows Event Logs in v4.21 and older versions
              • Event Records Summary vs. Event Records
            • Prefetch Analyzer
            • Shellbag Data Fields
          • Linux Analyzers
          • macOS Analyzers
            • Audit Event Analyzer
      • Investigation Hub
        • Using the Investigation Hub
        • Investigation Hub – Data Usage Statistics Dashboard
      • Repository Explorer
      • Evidence Repositories
        • Generating a SAS URL
      • File Explorer
        • File Explorer - FAQs
      • Tornado (Preview Version)
        • Tornado Installation Guide
          • Tornado Operating System Support
        • Updating Tornado
        • Tornado Demo
        • Getting Started with Tornado
          • Tornado Terminology
        • Tornado Collectors
          • Accessing Google Workspace
            • Service Account Creation
              • Enable Service Account Key Creation
          • Access Modes in O365
            • O365 license types
        • Tornado Troubleshooting & Feedback
        • Tornado FAQs
      • Fleet AI
      • Asset Isolation
      • Policies
      • Off-Network Responder
        • Setting Up a Custom Case Directory
        • biunzip
          • biunzip password file
      • Responder Proxy Support
      • Proxy Configuration on the Console
      • Console Audit Logs
    • Troubleshooting
      • Console CPU Profiling for Performance Issues
      • Understanding MSI Error Code 1618
      • How to gather logs for Troubleshooting
        • Collecting Console Log Files
        • Collecting Responder Log Files
        • Collecting Off-Network Responder Log Files
    • FAQs
      • Resolving the "Invalid Host Header. Host must be the Console Address" Error
      • How to download the collected evidence and artifacts?
      • How to gather logs for Troubleshooting
        • Collecting Console Log Files
        • Collecting Responder Log Files
        • Collecting Off-Network Responder Log Files
      • Responder troubleshooting
      • Understanding Port Usage
      • How many assets can connect to a single Console instance?
      • How do I enable SSL on Console?
      • Can I use AIR with EDR/XDR Products?
      • Can I integrate AIR with my SOAR/SIEM?
      • What external URLs are used?
      • Docker & Host System IP Conflict
      • Monitoring Responder and UI API's
      • How do I update Responders on assets?
      • How to reset the password of a user via the CLI?
      • Is there a way to move an asset from one Organization or Case to another?
      • Creating exclusions/exception rules for Responder on EPP and EDR Solutions
      • Anything missing?
  • General
    • Licenses - Open-Source Software List
Powered by GitBook
On this page

Was this helpful?

Export as PDF
  1. AIR Platform
  2. Features
  3. DRONE
  4. Analyzers

Cross Platform Analyzers

MITRE ATT&CK AnalyzerDynamo AnalyzerBrowser History Analyzer
PreviousAnalyzersNextMITRE ATT&CK Analyzer

Last updated 21 hours ago

Was this helpful?