Mandiant RedLine is one of the free tools that help in carrying out a digital forensic investigation.
Specifically, it is a monitoring tool that collects all processes and drivers from memory, the network history, network information, transmitted system files, registry data, and event log files.
The current version of the Mandiant RedLine application is RedLine 1.14 and its release date is June 12, 2015 . It is also an analysis tool that includes multiple improvements for usability. Mandiant RedLine can reveal malicious software that is “hidden”.
It also provides MD5 hashes which are files that contain the digital signatures of some other files so that the user understands that what they downloaded is not corrupted.
The MD5 hashes used by RedLine filter some of the entries in memory analysis.
RedLine also uses “Indicators of Compromise” (IOC) (called in Greek indicator of compromise).
They are virus signatures and IP addresses, MD5 hashes of malware (malicious) files and can be used for early detection of future attack attempts.
When we input the data into RedLine:
1) We create a collector (IOC search collector)
2) We run the analysis We prefer to forward it from a USB
3) We analyze the data From a collector , From a stored memory folder or from a previous analysis
Additionally it supports operating systems such as Windows XP, Windows Vista, Windows 7, Windows 8 (32-bit and 64-bit). The download of Redline is free and the file size is 66.2 MB.
Redline
MD5: F51F458F7A69F9EF8FFEC9693A4444C5
SHA-1: 60A972C62BF8AA6F33F133BDE5866A46F5164840
Release Notes: Redline 1.14 (PDF)
User Guide: Redline 1.14 (PDF)
Whitelist: Whitelist 1.0 for Redline (ZIP)
https://www.mandiant.com/resources/downloads/
Aριστέα Τούσια , Κωνσταντίνα Παϊταρίδου @Wikibook
