Skip to content

Latest commit

 

History

History
118 lines (66 loc) · 2.27 KB

File metadata and controls

118 lines (66 loc) · 2.27 KB

% FOX HUNT(1) Version 5 | Fox Documentation

NAME

fox — The Forensic Examiner's Swiss Army Knife

SYNOPSIS

| fox hunt [flags ...] [local | paths ...]

DESCRIPTION

Hunt suspicious activities by carving events from file(s). Please be aware that, using the --sort flag will buffer all found events in memory. For large sets of data this could be very slow and take a serious amount of memory. All timestamps will be normalized to UTC.

FLAGS

-a, --all

: Show logs with all severities.

-s, --sort

: Show logs sorted by timestamp.

-u, --uniq

: Show logs that are unique by XXH3 hash. The calculated hash has 64-bits and is highly unlikely, but still possible, to collide with the another key.

-j, --json

: Show logs as JSON objects.

-l, --jsonl

: Show logs as JSON lines.

-t, --triage

: Show logs in Triage format. Implies --sort and --uniq flags.

-p, --parquet

: Save logs as Parquet file.

Filter Flags

-N, --min=time

: Minimum event time in RFC3339 format. Example: 2026-12-31T12:00:00.0Z.

-X, --max=time

: Maximum event time in RFC3339 format. Example: 2026-12-31T12:00:00.0Z.

-R, --rule=file

: Filter using Sigma rules file.

Stream Flags

-U, --url=url

: Stream events using CEF schema to url.

-E, --ecs=url

: Stream events using ECS schema to url.

-H, --hec=url

: Stream events using HEC schema to url.

-A, --auth=token

: Use auth token with HEC streaming. Must be specified without the 'Splunk' prefix.

POSITIONAL ARGUMENTS

Globbing paths to open or '-' to read from STDIN(4). If local is specified as path, a built-in list of known locations will be processed.

EXAMPLES

$ fox hunt -t *.dd

: Hunt down critical events.

$ fox hunt -ap local

: Save local events as Parquet.

$ fox hunt -E http://127.0.0.1:8080 *.evtx

: Send events to an Elastic Stack.

BUGS

Please submit any issues with fox to the project's bug tracker: <_https://foxforensics.eu/issues_>

WWW

Please visit the project's homepage at: <https://foxforensics.eu>

SEE ALSO

fox(1), sort(1), uniq(1)