Where communities thrive

  • Join over 1.5M+ people
  • Join over 100K+ communities
  • Free without limits
  • Create your own community
Repo info
    @knsankar - GRR doesn't support dynamic labels. But note that, when creating hunts, you can limit the scope of a hunt to a particular OS or hostname prefix, using "OS" or "Regex" hunt rules.
    @mbushkov Yeah, the regex option is really useful
    How can I add a new output plugin
    i dont have CSV output plugin
    Never mind. I found out that the CSV plugin is deprecated google/grr#537
    @knsankar you can download results in a CSV format (or SQLite or YAML) for any flow or hunt if you click on "Download as" button in the Results tab.
    Yeah. Thanks
    Hello Guys , I have a problem is there any one here can assist

    After Successful installation of new release of grr AT Ubuntu 18 using Virtual Box with a bridged network adapter. After the successful installation i am able to open the admin Ui interface successfully but at any time I restart the VM , I am no able to connect any more to my grr server.

    Note: My Ip doesn't change during Restart . I also ensured the configuration for admin ui port as 8000 and forntend port as 8080 but they are still in-accessible after restarting.


    I am trying to intergrate GRR with Timesketch.

    Found few guides that suggests grr_fuse to mount grr files and run dftimewolf on them.

    The problem is I couldn’t find grr_fuse. I think, its deprecated.

    Is there anyother better way to integrate with Timesketch?

    5 replies

    I was facing some stability issue with mysql community server, so I tried to use MariaDB with grr.
    I am facing following error

    ‘''MySQLdb._exceptions.ProgrammingError: (1064, "You have an error in your SQL syntax; check the manual that corresponds to your MariaDB server version for the right syntax to use near '6)\n )' at line 3”)’''

    Is mariaDB not supported by grr?

    16 replies
    In GRR, once the machine is approved, how long the access remains?
    Is there a way to revoke the access?
    9 replies
    what is the canary mode in GRR UI?
    Tory Clasen
    Hello all. I just installed the server, but I can't seem to get the UI working. Did I do something wrong?
    Literally only installed the deb file and started the services.
    Tory Clasen
    It actually looks like the server is failing to start due to a python error:
    I0919 17:02:24.834474 139862652036928 server_logging.py:186] Writing log file to /usr/share/grr-server/lib/python3.6/site-packages/grr_response_core/var/log//GRRlog.txt
    Traceback (most recent call last):
    File "/usr/share/grr-server/bin/grr_console", line 8, in <module>
    File "/usr/share/grr-server/lib/python3.6/site-packages/grr_response_server/distro_entry.py", line 15, in Console
    File "/usr/share/grr-server/lib/python3.6/site-packages/absl/app.py", line 299, in run
    _run_main(main, args)
    File "/usr/share/grr-server/lib/python3.6/site-packages/absl/app.py", line 250, in _run_main
    File "/usr/share/grr-server/lib/python3.6/site-packages/grr_response_server/bin/console.py", line 72, in main
    File "/usr/share/grr-server/lib/python3.6/site-packages/grr_response_core/lib/utils.py", line 1329, in _OneTimeFunction
    _OneTimeFunction.result = fn(args, kwargs)
    File "/usr/share/grr-server/lib/python3.6/site-packages/grr_response_server/server_startup.py", line 88, in Init
    File "/usr/share/grr-server/lib/python3.6/site-packages/grr_response_server/data_store.py", line 100, in InitializeDataStore
    REL_DB = db.DatabaseValidationWrapper(cls())
    File "/usr/share/grr-server/lib/python3.6/site-packages/grr_response_server/databases/mysql.py", line 502, in init
    File "/usr/share/grr-server/lib/python3.6/site-packages/grr_response_server/databases/mysql.py", line 305, in _SetupDatabase
    ca_cert_path=ca_cert_path)) as conn:
    File "/usr/share/grr-server/lib/python3.6/site-packages/grr_response_server/databases/mysql.py", line 400, in _Connect
    File "/usr/share/grr-server/lib/python3.6/site-packages/grr_response_server/databases/mysql.py", line 154, in _SetSqlMode
    cursor.execute("SET SESSION sql_mode = %s", [",".join(filtered_components)])
    File "/usr/lib/python3/dist-packages/MySQLdb/cursors.py", line 253, in execute
    File "/usr/lib/python3/dist-packages/MySQLdb/cursors.py", line 155, in _warning_check
    w[1:3]), stacklevel=3)
    1 reply
    ⭕Alexander Rymdeko-Harvey
    Hey guys I'm trying to look for a specific file extensions through out the environment.
    1 reply
    ANy tips on how to use the file finder I keep getting issues
    anyone know how can we fix the fleetspeak installation error with exit status 1? tokenize . import sys setup tool with pip2?
    Maciej Duda
    hello guys,
    I don't understand what "interrogation" button does in the interface. is it something like IoC aquisition in fireeye HX?
    2 replies
    Do we have any documentation around capacity planning of GRR?
    1 reply
    Hi Folks, I have been trying to install GRR on Ubuntu 20.04 the steps here (https://grr-doc.readthedocs.io/en/latest/installing-grr-server/from-release-deb.html) but got an error "Sub-process /usr/bin/dpkg returned an error code" when installing. Does anyone know how to fix it ?
    When trying the docker image I get error 500
    Gunjan Yadu
    Hello. Myself Gunjan Yadu from IIT ( BHU ), Varanasi. I would like to contribute to GRR Rapid Response and participate in GSOC 2021. I am facing issues in setting up the project https://github.com/google/grr . Please guide me as I am new to open source
    Hey everybody.
    I tried to install the GRR server using Nginx. It is installed and shows the status active but I am not able to see anything on the browser. It just says unable to load the page.. any ideas what should I do ??
    1 reply
    Hello Everyone! I'm Mittul and I am pursuing master's in CS.
    I am interested in Modern user interface for YARA memory scans project idea.
    I want to know more about the tasks and challenges involved in this project.
    Can anyone Help?
    1 reply
    Ahamed Aaqib
    Hi Guys
    Hi, I have been playing around with this tool, I would like the ability to push tools to a system, run them and then pull back the results, is this possible? or is there an easy method to build in the functionality?
    1 reply
    Is there a way to update the clients version once the server version is update?
    2 replies
    Guys I have 2 doubts:
    1. Can we install GRR server as well as the client on the same machine
    2. Is running the GRR client binary file necessary every time we switch on the system
    Hello Everyone
    I want to export result to Elasticsearch
    buy i cant find out the document about that
    May everyone help with the problem?
    Many thanks,
    Cyrille Rebeca
    Tried deploying GRR server, however, when navigating to Management page, I get "Unauthorized", are there any steps to troubleshoot this? Thanks!
    Hasta Yaşlı Bakımı
    Psikoteknik Raporu
    Stilistlik Kursu
    Src Psikoteknik ve K Belgesi
    GRR have any user interface ?
    Łukasz Byjoś - 👨‍💻🇵🇱🇪🇺
    Hi, can I run GRR on single port? I want to use Cloudflare Tunnel but it work just with domain (so 433 port) and does not support other ports. For docker deployment I need to have 8000 and 8080 port :/