AChoir Windows Live Artifacts Acquisition Scripting Framework Logo

AChoir Windows Live Artifacts Acquisition Scripting Framework

0
Free
Visit Website

Every Incident Responder eventually comes to the conclusion that they need to script their favorite Live Acquisition utilities. I have seen these scripts written in numerous scripting languages - but oddly enough, all of these scripts tend to use many of the same freely available utilities - To do mostly the same things. It often takes an Incident Responder several years, along with lots of trial and error to settle on a set of utilities (and options) that both work and that provide relevant information on useful forensic artifacts. And even though Responders often use the same utilities and are scripting them in largely the same way, each Responder has to go through the same pain of building their own script in their (not so) favorite scripting language - figuring out how to quickly and consistently gather the artifacts of most value. Achoir is a Framework/Scripting Tool to standardize and simplify that process. #Versions (So Far): AChoir v0.01 First Version (05/30/15) AChoir v0.02 Add Variables: &Dir &Fil &Acq &Win AChoir v0.03 Add Hashing AChoir v0.04 Add FOR:, &FOR, &NUM Looping AChoir v0.05 Add CK

FEATURES

ALTERNATIVES

NBD is a userland implementation of the Network Block Device protocol, allowing for remote access to block devices over a network.

Magnet ACQUIRE offers robust data extraction capabilities for digital forensics investigations, supporting a wide range of devices.

A command-line utility for extracting human-readable text from binary files.

Hindsight is a free tool for analyzing web artifacts from Google Chrome/Chromium browsers and presenting the data in a timeline for forensic analysis.

Collects and organizes Linux OS data for detailed analysis and incident response.

A framework for orchestrating forensic collection, processing, and data export.

Dissect is a digital forensics & incident response framework that simplifies the analysis of forensic artefacts from various disk and file formats.

A python module for orchestrating content acquisitions and analysis via Amazon SSM.

PINNED