Overview
Colander web platform is a case and digital investigation platform that integrates seamlessly with the hardware and software components. Colander provides a centralized hub for managing investigations, streamlining workflows, and enabling effective collaboration among team members.
Quick start
Spin up Colander on your own machine and open your first case in just a few commands.
Architecture
Colander relies on several services:
Deployment
This guide walks you through deploying Colander on a dedicated server.
Docker Compose (standalone)
Prefer to skip Ansible and drive Docker Compose yourself? The same colander-ansible repository ships a self-service docker/ folder: pick only the components you need, start the full stack in one command, or hand it to your own provisioning tool.
Account administration
Once Colander is deployed and running, the system administrator has to create a first account with administrative rights for both Colander and Threatr. To do so, the system administrator has to run the following command on the server running Colander:
Graphical interface
The graphical interface of Colander allows to navigate through the different workspaces as well as easily switching from one case to another or quickly searching for entities within a selected case or within all the userβs cases.
Case management
In the context of digital investigation, the effective organization and management of cases are imperative. As a digital investigator you focus on documenting incident, the utilization of Colander serves as a comprehensive platform to streamline and document investigative efforts. This document explain how to use Colander for organizing and managing digital investigation cases.
Entity management
Entity creation
Artifact management
Colander streamlines the handling and preservation of digital evidence, maintaining chain of custody and maximizing admissibility in legal proceedings.
Knowledge management
Knowledge management is an ongoing process of capturing, organizing, and sharing the knowledge and expertise gained from digital investigations. It aims to create a repository of best practices, guidelines, and case studies that can be leveraged by future investigators to improve their investigative techniques and decision-making processes.
Collaboration
Teams in Colander are the only way to share cases with other users. To create a team, go in Colander > Collaborate > Teams and give a name.
Advanced
12 items