Truxton Forensic Rack

From truxwiki.com
Jump to navigation Jump to search

The Truxton Forensic Rack is a 7 foot tall rack populated with hardware dedicated to forensic processing. It has a Yellowbrick database appliance, seven dedicated loader/exploitation machines and 1PB of usable depot storage. With everything separated, it gives us many knobs to turn for loading.

Hardware

Here's how the hardware is stacked:

U42 Network Switch
U27 Yellowbrick
U26 Yellowbrick Manager 0
U25 Yellowbrick Manager 1
U23 KVM Server
U22 Keyboard and Monitor
U13 Loader Node 7
U11 Loader Node 6
U09 Loader Node 5
U07 Loader Node 4
U05 Loader Node 3
U03 Loader Node 2
U01 Loader Node 1

Installing Hardware

Normally you won't have to do this but should you want to move the hardware out of the existing rack an into a different one, populate the new rack from the bottom up.

  1. Locate Server Node 1
    1. Install the rails for the server into the rack position
    2. Slide the server onto the rails
  2. Repeat for the remaining servers working your way up the rack
  3. Install rails for KVM
  4. Install KVM
  5. Install rails for Yellowbrick Management Node 1
  6. Install Yellowbrick Management Node 1
  7. Install rails for Yellowbrick Management Node 2
  8. Install Yellowbrick Management Node 2
  9. Install rails for Yellowbrick Server
  10. Install Yellowbrick Server
  11. Populate Yellowbrick Server with 9 blades
  12. Fill the empty spaces in Yellowbrick Server with empty blade enclosures
  13. Install rails for network switches
  14. Install network switches
  15. Add the hundreds of cables

Power Up Sequence

Generally speaking, you start the rack from the top down.

  1. Turn on the network switches
  2. Turn on Yellowbrick Management Node 1
  3. Turn on Yellowbrick Management Node 2
  4. Turn on Yellowbrick server
  5. Turn on the KVM switch
  6. Turn on the Servers (7 through 1)

It will take several minutes for everything to boot.

Installing Software

Prior to software installation, several decisions must be made:

  1. Where are temporary files going to go? ETL processes may have to write files to a temporary location during forensic processing. This location should ideally be on an SSD for speed.
  2. Where are the hashsets going to go? This should most definitely be on an SSD local to the server.
  3. Where are the SOLR indexes going to go?
  4. Where are the software installation packages?
  5. Where are the PostgreSQL databases going to go?

Defaults as Shipped

The Truxton Forensic Rack is delivered with the following defaults:

What Where
Temporary Files D:\Temp
Hash Sets D:\Hashsets
SOLR C:\Clusterstorage\Scratch\UXX\SOLR
Software Installers C:\Clusterstorage\SampleData\Rack Management\Software
Databases D:\Truxton Data\data

Each server node is pre-installed with Notepad++ and dBeaver tools.

Truxton was installed to write data to the D:\Truxton Data folder.