← All cheat sheets

REDLINE

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

Free endpoint investigation tool by Mandiant/FireEye. Collects
and analyzes memory, files, registry, and event logs for IOCs.

DOWNLOAD#

# Free from Mandiant (Windows only)
# https://www.fireeye.com/services/freeware/redline.html
# Requires registration

COLLECTION METHODS#

# 1. Standard Collector (comprehensive)
#    Analysis > Create Standard Collector
#    - Collects memory, files, registry, event logs, etc.
#    - Deploy to target machine
#    - Run RunRedlineAudit.bat on target
#    - Copy results back for analysis

# 2. Comprehensive Collector
#    Analysis > Create Comprehensive Collector
#    - Everything in Standard plus additional artifacts
#    - Slower but more thorough

# 3. IOC Search Collector
#    Analysis > Create IOC Search Collector
#    - Targeted search using OpenIOC indicators
#    - Fastest collection method
#    - Import IOCs from MISP, threat intel feeds

# 4. Memory Image Analysis
#    Analysis > Open Memory Image
#    - Import existing memory dumps (.raw, .dmp)
#    - Analyze processes, network, handles

CREATING A COLLECTOR#

1. Open Redline > Create Collector
2. Choose collector type (Standard/Comprehensive/IOC)
3. Select artifacts to collect:
   - Memory
   - Disk
   - System information
   - User activity
   - Network
   - Services and drivers
   - Tasks
   - Registry
   - Event logs
   - Prefetch
   - Web history
4. Choose output directory
5. Copy collector folder to target
6. Run RunRedlineAudit.bat as Administrator on target
7. Wait for collection to complete
8. Copy results back to analysis machine

ANALYSIS FEATURES#

# Process analysis
  - Process tree view
  - Loaded DLLs and handles
  - Memory strings
  - Digital signature verification
  - VirusTotal integration
  - Suspicious process flagging

# Timeline analysis
  - Chronological event timeline
  - Filter by date range
  - Filter by event type
  - Color-coded severity

# File analysis
  - File listing with metadata
  - MD5/SHA1/SHA256 hashes
  - File signature verification
  - Downloaded files tracking
  - Recently accessed files

# Registry analysis
  - Autorun entries
  - UserAssist
  - Shimcache
  - Recent docs
  - USB history

# Network analysis
  - Active connections
  - DNS cache
  - ARP cache
  - Listening ports
  - URL history

# Event log analysis
  - Security events
  - System events
  - Application events
  - PowerShell logs
# Import OpenIOC files
# Redline matches IOCs against collected data
# Results show hits per IOC

# IOC types supported:
  - File hashes (MD5, SHA1, SHA256)
  - File names and paths
  - Registry keys and values
  - DNS names
  - IP addresses
  - Process names
  - Service names
  - Mutex names

# Create IOCs:
  - Use Mandiant IOC Editor
  - Import from threat intel platforms
  - Convert from STIX/YARA

WHITELIST MANAGEMENT#

# Reduce noise by whitelisting known-good items
# Analysis > Manage Whitelists
# Import NSRL hash set for known software
# Create custom whitelists for organization

TIMELINE WORKFLOW#

# TimeWrinkle: filter timeline to specific time periods
# TimeCrunch: focus on time ranges with high activity

1. Import analysis session
2. Review auto-flagged items (MRI score)
3. Use TimeWrinkle to narrow time range
4. Look for:
   - Process creation around incident time
   - File modifications
   - Registry changes
   - Network connections
   - Service installations
   - Scheduled task creation
5. Document findings per timeline entry
6. Export report

TIPS#

  - Deploy collector via USB for isolated endpoints
  - Run as Administrator for complete collection
  - Memory collection reveals in-memory-only threats
  - IOC Search Collector is fastest for known threats
  - Timeline analysis is Redline's strongest feature
  - TimeWrinkle/TimeCrunch focus investigation quickly
  - Whitelist known-good to reduce false positives
  - Export results for correlation with other tools
  - Combine with Volatility for deeper memory analysis
  - Standard Collector is good balance of speed and coverage
  - Windows-only tool — use on Windows analysis workstation
  - Consider Cyber Triage or Velociraptor as modern alternatives