{"id":2995,"date":"2015-04-11T16:34:18","date_gmt":"2015-04-11T16:34:18","guid":{"rendered":"http:\/\/www.hexacorn.com\/blog\/?p=2995"},"modified":"2015-04-11T16:34:18","modified_gmt":"2015-04-11T16:34:18","slug":"introducing-filighting-and-the-future-of-dfir-tools-part-3-more-examples","status":"publish","type":"post","link":"https:\/\/www.hexacorn.com\/blog\/2015\/04\/11\/introducing-filighting-and-the-future-of-dfir-tools-part-3-more-examples\/","title":{"rendered":"Introducing filighting and the future of DFIR tools, part 3 &#8211; more examples"},"content":{"rendered":"<p>I have been toying around with the script trying it on various folders and the results are quite promising.<\/p>\n<p>Here is a bunch of examples &#8211; screenshots + interactive demos. Note that some JSON files may take a long time to load so please be patient.<\/p>\n<ul>\n<li><a href=\"https:\/\/www.hexacorn.com\/examples\/2015-04-11\/cluster_opera.html\">Opera 26<\/a>\n<ul>\n<li>Quite a nice graph &#8211; all files had at least one reference<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p><a href=\"https:\/\/www.hexacorn.com\/blog\/wp-content\/uploads\/2015\/04\/cluster_opera26.png\"><img decoding=\"async\" loading=\"lazy\" class=\"aligncenter size-medium wp-image-2996\" src=\"https:\/\/www.hexacorn.com\/blog\/wp-content\/uploads\/2015\/04\/cluster_opera26-300x239.png\" alt=\"cluster_opera26\" width=\"300\" height=\"239\" srcset=\"https:\/\/www.hexacorn.com\/blog\/wp-content\/uploads\/2015\/04\/cluster_opera26-300x239.png 300w, https:\/\/www.hexacorn.com\/blog\/wp-content\/uploads\/2015\/04\/cluster_opera26.png 952w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<ul>\n<li><a href=\"https:\/\/www.hexacorn.com\/examples\/2015-04-11\/cluster_firefox.html\">Firefox 35<\/a>\n<ul>\n<li>Quite a nice graph as well &#8211; all files had at least one reference<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p><a href=\"https:\/\/www.hexacorn.com\/blog\/wp-content\/uploads\/2015\/04\/cluster_firefox.png\"><img decoding=\"async\" loading=\"lazy\" class=\"aligncenter size-medium wp-image-2998\" src=\"https:\/\/www.hexacorn.com\/blog\/wp-content\/uploads\/2015\/04\/cluster_firefox-300x254.png\" alt=\"cluster_firefox\" width=\"300\" height=\"254\" srcset=\"https:\/\/www.hexacorn.com\/blog\/wp-content\/uploads\/2015\/04\/cluster_firefox-300x254.png 300w, https:\/\/www.hexacorn.com\/blog\/wp-content\/uploads\/2015\/04\/cluster_firefox.png 698w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<ul>\n<li><a href=\"https:\/\/www.hexacorn.com\/examples\/2015-04-11\/cluster_office.html\">Office 15<\/a>\n<ul>\n<li>There is so many files that it is not very readable<\/li>\n<li>BUT out of 3K+ files, only 17 didn&#8217;t have any reference!<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p><a href=\"https:\/\/www.hexacorn.com\/blog\/wp-content\/uploads\/2015\/04\/cluster_office15.png\"><img decoding=\"async\" loading=\"lazy\" class=\"aligncenter size-medium wp-image-2997\" src=\"https:\/\/www.hexacorn.com\/blog\/wp-content\/uploads\/2015\/04\/cluster_office15-300x154.png\" alt=\"cluster_office15\" width=\"300\" height=\"154\" srcset=\"https:\/\/www.hexacorn.com\/blog\/wp-content\/uploads\/2015\/04\/cluster_office15-300x154.png 300w, https:\/\/www.hexacorn.com\/blog\/wp-content\/uploads\/2015\/04\/cluster_office15-1024x525.png 1024w, https:\/\/www.hexacorn.com\/blog\/wp-content\/uploads\/2015\/04\/cluster_office15.png 1397w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<ul>\n<li><a href=\"https:\/\/www.hexacorn.com\/examples\/2015-04-11\/cluster_notepadplus.html\">Notepad ++<\/a>\n<ul>\n<li>Probably the worst case I have seen so far &#8211; lots of clusters and orphaned files<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p><a href=\"https:\/\/www.hexacorn.com\/blog\/wp-content\/uploads\/2015\/04\/cluster_notepadplus.png\"><img decoding=\"async\" loading=\"lazy\" class=\"aligncenter size-medium wp-image-2999\" src=\"https:\/\/www.hexacorn.com\/blog\/wp-content\/uploads\/2015\/04\/cluster_notepadplus-300x171.png\" alt=\"cluster_notepadplus\" width=\"300\" height=\"171\" srcset=\"https:\/\/www.hexacorn.com\/blog\/wp-content\/uploads\/2015\/04\/cluster_notepadplus-300x171.png 300w, https:\/\/www.hexacorn.com\/blog\/wp-content\/uploads\/2015\/04\/cluster_notepadplus-1024x584.png 1024w, https:\/\/www.hexacorn.com\/blog\/wp-content\/uploads\/2015\/04\/cluster_notepadplus.png 1433w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<ul>\n<li><a href=\"https:\/\/www.hexacorn.com\/examples\/2015-04-11\/cluster_vmware.html\">VMWare 11<\/a>\n<ul>\n<li>Not too bad, lot of files are referenced, just a few stand out<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p><a href=\"https:\/\/www.hexacorn.com\/blog\/wp-content\/uploads\/2015\/04\/cluster_vmware.png\"><img decoding=\"async\" loading=\"lazy\" class=\"aligncenter size-medium wp-image-3000\" src=\"https:\/\/www.hexacorn.com\/blog\/wp-content\/uploads\/2015\/04\/cluster_vmware-300x234.png\" alt=\"cluster_vmware\" width=\"300\" height=\"234\" srcset=\"https:\/\/www.hexacorn.com\/blog\/wp-content\/uploads\/2015\/04\/cluster_vmware-300x234.png 300w, https:\/\/www.hexacorn.com\/blog\/wp-content\/uploads\/2015\/04\/cluster_vmware.png 850w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>I have been toying around with the script trying it on various folders and the results are quite promising. Here is a bunch of examples &#8211; screenshots + interactive demos. Note that some JSON files may take a long time &hellip; <a href=\"https:\/\/www.hexacorn.com\/blog\/2015\/04\/11\/introducing-filighting-and-the-future-of-dfir-tools-part-3-more-examples\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[39,19,40],"tags":[],"_links":{"self":[{"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/posts\/2995"}],"collection":[{"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/comments?post=2995"}],"version-history":[{"count":2,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/posts\/2995\/revisions"}],"predecessor-version":[{"id":3002,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/posts\/2995\/revisions\/3002"}],"wp:attachment":[{"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/media?parent=2995"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/categories?post=2995"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/tags?post=2995"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}