Import and export a case
Colander can export a whole case as an archive and import it back, on the same instance or on another one. It allows you to transfer a case from one organization to another, to keep a copy of a case, or to move your investigations to a new Colander server.
Artifact acquisition
Abstract
Knowledge graph
In the realm of digital investigations, where the volume and complexity of data can be overwhelming, knowledge graphs emerge as a sophisticated tool for organizing, analyzing, and extracting meaningful insights. These structured representations of knowledge, akin to semantic networks, connect entities and their interrelationships, providing a cohesive framework for comprehending the intricacies of digital environments.
Import knowledge
Colander supports multiple data formats that can be directly imported into a case:
Share knowledge
Facilitating the exchange of knowledge among investigators, both within the same organization and across different organizations, is crucial for promoting learning and continuous improvement. This can be achieved through formal knowledge sharing feeds. Colander supports export feeds accessible via a password-protected URL giving access to the knowledge in different formats such as JSON, STIX2, MISP, CSV, dot and Mermaid.
PiRogue fleet
Colander can manage your PiRogues, whether they are physical devices or virtual instances. Once a PiRogue is enrolled, you can monitor its health, configure it remotely from Colander, and use it to monitor devices in your cases. All the PiRogues you can access are listed in the PiRogue fleet entry of the main menu.
Device monitoring
Device monitoring lets you analyze the network traffic of a device with an enrolled PiRogue and see the results directly in your case: the network flows of the device and the security alerts raised by Suricata. It is designed to help organizations assist people at risk who do not have physical access to a PiRogue, using the PiRogue as an emergency VPN server.
Network traffic analysis
Network traffic analysis
Network traffic decryption
Network traffic decryption
Chain of custody
In the intricate domain of digital forensics, maintaining confidentiality is paramount to protect sensitive information and ensure the integrity of investigations. Two widely adopted confidentiality frameworks, Traffic Light Protocol (TLP) and Permissible Actions Protocol (PAP), provide structured guidelines for sharing and restricting access to sensitive data. These frameworks empower digital forensic practitioners to navigate the delicate balance between information sharing and confidentiality.
External sources
Colander allows you to retrieve information from 3rd-party services such as VirusTotal, MISP and OTX Alien Vault. To do so, Colander relies on Threatr which operates as a bridge and translator between Colander and the external services.
REST API
A Python 3 library abstracting the REST API of Colander is available on GitHub.