AChoir Windows Live Artifacts Acquisition Scripting Framework Logo

AChoir Windows Live Artifacts Acquisition Scripting Framework

0
Free
Visit Website

Every Incident Responder eventually comes to the conclusion that they need to script their favorite Live Acquisition utilities. I have seen these scripts written in numerous scripting languages - but oddly enough, all of these scripts tend to use many of the same freely available utilities - To do mostly the same things. It often takes an Incident Responder several years, along with lots of trial and error to settle on a set of utilities (and options) that both work and that provide relevant information on useful forensic artifacts. And even though Responders often use the same utilities and are scripting them in largely the same way, each Responder has to go through the same pain of building their own script in their (not so) favorite scripting language - figuring out how to quickly and consistently gather the artifacts of most value. Achoir is a Framework/Scripting Tool to standardize and simplify that process. #Versions (So Far): AChoir v0.01 First Version (05/30/15) AChoir v0.02 Add Variables: &Dir &Fil &Acq &Win AChoir v0.03 Add Hashing AChoir v0.04 Add FOR:, &FOR, &NUM Looping AChoir v0.05 Add CK

FEATURES

ALTERNATIVES

A comprehensive guide to incident response and computer forensics, covering the entire lifecycle of incident response and remediation.

Open source tool for generating YARA rules about installed software from a running OS.

A powerful OSINT tool for creating custom templates for data extraction and analysis

A digital artifact extraction framework for extracting data from volatile memory (RAM) samples, providing visibility into the runtime state of a system.

Highlighter is a FireEye Market app that integrates with FireEye products to provide enhanced cybersecurity capabilities.

iOSForensic is a Python tool for forensic analysis on iOS devices, extracting files, logs, SQLite3 databases, and .plist files into XML.

Documentation project for Digital Forensics Artifact Repository

Easy-to-use live forensics toolbox for Linux endpoints with various capabilities such as process inspection, memory analysis, and YARA scanning.