AChoir Windows Live Artifacts Acquisition Scripting Framework Logo

AChoir Windows Live Artifacts Acquisition Scripting Framework

0
Free
Visit Website

Every Incident Responder eventually comes to the conclusion that they need to script their favorite Live Acquisition utilities. I have seen these scripts written in numerous scripting languages - but oddly enough, all of these scripts tend to use many of the same freely available utilities - To do mostly the same things. It often takes an Incident Responder several years, along with lots of trial and error to settle on a set of utilities (and options) that both work and that provide relevant information on useful forensic artifacts. And even though Responders often use the same utilities and are scripting them in largely the same way, each Responder has to go through the same pain of building their own script in their (not so) favorite scripting language - figuring out how to quickly and consistently gather the artifacts of most value. Achoir is a Framework/Scripting Tool to standardize and simplify that process. #Versions (So Far): AChoir v0.01 First Version (05/30/15) AChoir v0.02 Add Variables: &Dir &Fil &Acq &Win AChoir v0.03 Add Hashing AChoir v0.04 Add FOR:, &FOR, &NUM Looping AChoir v0.05 Add CK

FEATURES

ALTERNATIVES

A user-friendly and fast Forensic Analysis tool with features like tagging files and generating preview reports.

Advanced computer forensics software with efficient features.

XMLStarlet offers a suite of command line utilities for manipulating and querying XML documents.

A forensic research tool for gathering forensic traces on Android and iOS devices, supporting the use of public indicators of compromise.

A comprehensive Linux log analysis tool that streamlines the investigation of security incidents by extracting and organizing critical details from supported log files.

A script to extract subdomains/emails for a given domain using SSL/TLS certificate dataset on Censys.

Open Source computer forensics platform with modular design for easy automation and scripting.

DFIR ORC Documentation provides detailed instructions for setting up the build environment and deploying the tool.

CyberSecTools logoCyberSecTools

Explore the largest curated directory of cybersecurity tools and resources to enhance your security practices. Find the right solution for your domain.

Copyright © 2024 - All rights reserved