is doorman still supported? it doesnt look like a...
# doorman
z
is doorman still supported? it doesnt look like any significant changes have been made in the last 4 yearrs?
s
Not really, no. The original creator has moved on and the other solutions have out-paced Doorman. I’d recommend Kolide Fleet, which is also free & open-source but has a whole company supporting it.
z
That's what I thought, it's the same with SGT as well.
j
osctrl is another option, fully open-source and it supports file carving, which Fleet unfortunately does not
Full disclosure, I wrote osctrl
z
I haven't delved too much into file carving, so I don't know what that gives me
j
Extraction of files/directories from machines that are running osquery
z
for fim?
j
that is different, you can enable that via configuration though, this is actually extracting the contents of files/directories
z
for what purposes though?
j
investigations, checking logs or configuration files