# mozilla/mig

Distributed & real time digital forensics at the speed of the cloud

Repository: https://github.com/mozilla/mig
Canonical: https://ross.abutalabs.com/products/mig
Homepage: http://mig.mozilla.org/
Language: Go
License: MPL-2.0
License Family: copyleft
Archived: true
Last push: 2019-09-13T23:40:11+00:00

## Health v2 (maintenance only)
Score: 10/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 0, release rhythm 35, longevity 100
- inputs: {"age_days": 4740, "days_push": 2546, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases, archived
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1202, forks 230 (observed 2026-08-28T04:03:58.484860+00:00)

## What it is
MIG (Mozilla InvestiGator) is a distributed platform for real-time digital forensics and endpoint investigation, using agents installed across an infrastructure that can be queried to inspect file systems, network state, memory, and configuration. It is written in Go and officially deprecated by Mozilla, which no longer maintains or uses the code.

## Use cases
- investigate compromised endpoints across a fleet in real time
- search all servers for files matching a known malicious hash
- inspect network connections and memory on remote machines
- run system audits across an infrastructure
- respond quickly to a newly disclosed vulnerability by checking exposure at scale

## When to choose
- you need real-time, distributed forensic queries across many endpoints
- you want a self-hosted agent-based investigation platform and are willing to maintain a fork

## When to avoid
- you want an actively maintained project with upstream support
- you need vulnerability management or log analysis features that were never completed
- you prefer modern alternatives like osquery-based tooling

## Facets
- artifact type: service
- maturity: abandoned
- function: security, monitoring, vulnerability-scanning
- domain: security, developer-tools, infrastructure-as-code
- platform: windows, go, self-hosted
- tags: digital-forensics, endpoint-investigation, incident-response, distributed-agents, deprecated, linux, macos, docker

## Member repositories
- mozilla/mig (main) score 10

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:03:58.484860+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T06:20:37.079457+00:00, confidence not recorded.
  - readme: https://github.com/mozilla/mig (fetched 2026-08-28T04:03:58.484860+00:00, sha 8b0ddbd1fca4)
- Data as of 2026-08-30T08:39:29.467469+00:00.
