- Home
- Security Operations
- Digital Forensics and Incident Response
- AChoir Windows Live Artifacts Acquisition Scripting Framework
AChoir Windows Live Artifacts Acquisition Scripting Framework
A framework/scripting tool to standardize and simplify the process of scripting favorite Live Acquisition utilities for Incident Responders.

AChoir Windows Live Artifacts Acquisition Scripting Framework
A framework/scripting tool to standardize and simplify the process of scripting favorite Live Acquisition utilities for Incident Responders.
AChoir Windows Live Artifacts Acquisition Scripting Framework Description
Every Incident Responder eventually comes to the conclusion that they need to script their favorite Live Acquisition utilities. I have seen these scripts written in numerous scripting languages - but oddly enough, all of these scripts tend to use many of the same freely available utilities - To do mostly the same things. It often takes an Incident Responder several years, along with lots of trial and error to settle on a set of utilities (and options) that both work and that provide relevant information on useful forensic artifacts. And even though Responders often use the same utilities and are scripting them in largely the same way, each Responder has to go through the same pain of building their own script in their (not so) favorite scripting language - figuring out how to quickly and consistently gather the artifacts of most value. Achoir is a Framework/Scripting Tool to standardize and simplify that process. #Versions (So Far): AChoir v0.01 First Version (05/30/15) AChoir v0.02 Add Variables: &Dir &Fil &Acq &Win AChoir v0.03 Add Hashing AChoir v0.04 Add FOR:, &FOR, &NUM Looping AChoir v0.05 Add CK
FEATURED
Password manager with end-to-end encryption and identity protection features
VPN service providing encrypted internet connections and privacy protection
Fractional CISO services for B2B companies to accelerate sales and compliance
Stay Updated with Mandos Brief
Get the latest cybersecurity updates in your inbox
TRENDING CATEGORIES
POPULAR
Security platform that provides protection, monitoring and governance for enterprise generative AI applications and LLMs against various threats including prompt injection and data poisoning.
A threat intelligence aggregation service that consolidates and summarizes security updates from multiple sources to provide comprehensive cybersecurity situational awareness.
Fabric Platform is a cybersecurity reporting solution that automates and standardizes report generation, offering a private-cloud platform, open-source tools, and community-supported templates.
A weekly newsletter providing cybersecurity leadership insights, industry updates, and strategic guidance for security professionals advancing to management positions.