<?xml version="1.0" encoding="UTF-8"?>
<!-- generator="FeedCreator 1.8" -->
<?xml-stylesheet href="https://xn--e-br-noa.de/lib/exe/css.php?s=feed" type="text/css"?>
<rdf:RDF
    xmlns="http://purl.org/rss/1.0/"
    xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
    xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
    xmlns:dc="http://purl.org/dc/elements/1.1/">
    <channel rdf:about="https://xn--e-br-noa.de/feed.php">
        <title>E-Bärs Xopedia - soc:tools</title>
        <description></description>
        <link>https://xn--e-br-noa.de/</link>
        <image rdf:resource="https://xn--e-br-noa.de/lib/exe/fetch.php?media=wiki:dokuwiki.svg" />
       <dc:date>2026-06-10T21:34:28+00:00</dc:date>
        <items>
            <rdf:Seq>
                <rdf:li rdf:resource="https://xn--e-br-noa.de/doku.php?id=soc:tools:ewf&amp;rev=1781077623&amp;do=diff"/>
                <rdf:li rdf:resource="https://xn--e-br-noa.de/doku.php?id=soc:tools:kibana&amp;rev=1781089071&amp;do=diff"/>
                <rdf:li rdf:resource="https://xn--e-br-noa.de/doku.php?id=soc:tools:splunk&amp;rev=1781096647&amp;do=diff"/>
                <rdf:li rdf:resource="https://xn--e-br-noa.de/doku.php?id=soc:tools:start&amp;rev=1781096671&amp;do=diff"/>
                <rdf:li rdf:resource="https://xn--e-br-noa.de/doku.php?id=soc:tools:volatility&amp;rev=1781081888&amp;do=diff"/>
                <rdf:li rdf:resource="https://xn--e-br-noa.de/doku.php?id=soc:tools:wireshark&amp;rev=1780993286&amp;do=diff"/>
            </rdf:Seq>
        </items>
    </channel>
    <image rdf:about="https://xn--e-br-noa.de/lib/exe/fetch.php?media=wiki:dokuwiki.svg">
        <title>E-Bärs Xopedia</title>
        <link>https://xn--e-br-noa.de/</link>
        <url>https://xn--e-br-noa.de/lib/exe/fetch.php?media=wiki:dokuwiki.svg</url>
    </image>
    <item rdf:about="https://xn--e-br-noa.de/doku.php?id=soc:tools:ewf&amp;rev=1781077623&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2026-06-10T07:47:03+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>EWF</title>
        <link>https://xn--e-br-noa.de/doku.php?id=soc:tools:ewf&amp;rev=1781077623&amp;do=diff</link>
        <description>EWF</description>
    </item>
    <item rdf:about="https://xn--e-br-noa.de/doku.php?id=soc:tools:kibana&amp;rev=1781089071&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2026-06-10T10:57:51+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>Kibana</title>
        <link>https://xn--e-br-noa.de/doku.php?id=soc:tools:kibana&amp;rev=1781089071&amp;do=diff</link>
        <description>Kibana

Query Basics
 @timestamp &gt;= “2023-01-01”  Timestamp  (X AND Y) OR Z  
Lucene

	*  Turn off KQL to use the Lucene query syntax

Fuzzy
 fu~~y  fuzzy operator  “server error”~4  “slop value” -&gt; server and error up to 4 positions apart</description>
    </item>
    <item rdf:about="https://xn--e-br-noa.de/doku.php?id=soc:tools:splunk&amp;rev=1781096647&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2026-06-10T13:04:07+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>Splunk</title>
        <link>https://xn--e-br-noa.de/doku.php?id=soc:tools:splunk&amp;rev=1781096647&amp;do=diff</link>
        <description>Splunk


# list all indexes, cmdline: splunk list index
| eventcount summarize=false index=* | dedup index | fields index

sourcetype=access_combined error | top 5 uri

[+|-]&lt;integer&gt;&lt;unit&gt;@&lt;snap_time_ unit&gt;

&quot;error earliest=-1d@d latest=h@h&quot;

#subsearch
sourcetype=syslog [ search login error | return 1 user ]


source=&quot;/var/log/myapp/access.log&quot; status=404

host=&quot;myblog&quot; source=&quot;/var/log/syslog&quot; Fatal

index=* OR index=_* sourcetype=generic_logs | search Cybersecurity | head 10000

#ipv4
| rege…</description>
    </item>
    <item rdf:about="https://xn--e-br-noa.de/doku.php?id=soc:tools:start&amp;rev=1781096671&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2026-06-10T13:04:31+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>Tools</title>
        <link>https://xn--e-br-noa.de/doku.php?id=soc:tools:start&amp;rev=1781096671&amp;do=diff</link>
        <description>Tools

SIEM

	*  Kibana
	*  Splunk

Network

	*  Wireshark

IR

	*  velociraptor
		*  remote artefact collection and administration

	*  iris
		*  Collaborative Incident Response Platform

	*  x_ways
	*  axiom
	*  f_Response
	*  arsenal_image_mounter
	*  magnet_ram_capture
	*  exiftool
	*  sqlite_database_browser
	*  ost_pst_viewer
	*  registry_viewer
	*  regripper
	*  ghidra

Commandline

	*  evtwalk
		*  Parse Windows Event Logs</description>
    </item>
    <item rdf:about="https://xn--e-br-noa.de/doku.php?id=soc:tools:volatility&amp;rev=1781081888&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2026-06-10T08:58:08+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>Volatility</title>
        <link>https://xn--e-br-noa.de/doku.php?id=soc:tools:volatility&amp;rev=1781081888&amp;do=diff</link>
        <description>Volatility


pipx install volatility3

pipx ensurepath 
pipx completions


* Install symbols tables from github
&lt;https://github.com/volatilityfoundation/volatility3&gt;

Windows Basics

&lt;https://volatility3.readthedocs.io/en/latest/volatility3.plugins.windows.html&gt;


vol -f &lt;image&gt; windows.info
vol -f &lt;image&gt; windows.pstree
windows.psscan
windows.pslist

vol.py -f “/path/to/file” -o “/path/to/dir” windows.dumpfiles ‑‑pid &lt;PID&gt;
vol.py -f “/path/to/file” -o “/path/to/dir” windows.memmap ‑‑dump ‑‑pid …</description>
    </item>
    <item rdf:about="https://xn--e-br-noa.de/doku.php?id=soc:tools:wireshark&amp;rev=1780993286&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2026-06-09T08:21:26+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>Wireshark</title>
        <link>https://xn--e-br-noa.de/doku.php?id=soc:tools:wireshark&amp;rev=1780993286&amp;do=diff</link>
        <description>Wireshark

Display Filters

Network
ip.src == #ip  ip.dst == #ip  ip.addr  src or dst (careful with negation!)tcp.srcport == #port  tcp.dstport == #port          eth.addr[0:3]==00:06:5B  Filter for manufacturer (example: Dell)           
DNS

dns.qry.name ==</description>
    </item>
</rdf:RDF>
