ir-rescue Logo

ir-rescue

A set of scripts for collecting forensic data from Windows and Unix systems respecting the order of volatility.

488
Visit website
Compare
Compare
0
MCPThe entire cybersecurity market, one prompt awayTry MCP Access

ir-rescue Description

ir-rescue is composed of two sister scripts that collect a myriad of forensic data from 32-bit and 64-bit Windows systems (ir-rescue-win) and from Unix systems (ir-rescue-nix). The scripts respect the order of volatility and artifacts that are changed with the execution (e.g., prefetch files on Windows) and are intended for incident response use at different stages in the analysis and investigation process. ir-rescue-win is fully written in Batch and can be set to perform comprehensive and customized acquisitions of specific types of live data and of historical data from available Volume Shadow Copy Service (VSS) copies. ir-rescue-win makes use of built-in Windows commands and well-known third party utilities from Sysinternals and NirSoft, for instance, some being open-source. PowerShell and the Windows Management Instrumentation (WMI) are not used in order to make ir-rescue-win transversally compatible. ir-rescue-nix is written in Bash (v4+) and makes use of built-in Unix commands. Some commands used might not be POSIX-compliant and therefore might not be available on some Unix-like systems or variants, especially on older operating systems.

ir-rescue FAQ

Common questions about ir-rescue including features, pricing, alternatives, and user reviews.

ir-rescue is A set of scripts for collecting forensic data from Windows and Unix systems respecting the order of volatility.. It is a Security Operations solution designed to help security teams with Windows Forensics.

Have more questions? Browse our categories or search for specific tools.

ALTERNATIVES

Cyber Triage Cyber Triage Collector Logo

Standalone DFIR data collector for Windows systems with adaptive collection

0
libregf Logo

A library for accessing and parsing Windows NT Registry File (REGF) format files, designed for digital forensics and registry analysis applications.

0
FastIR Collector Logo

Tool for live forensics acquisition on Windows systems, collecting artefacts for early compromise detection.

0
RegRipper 3.0 Logo

Automated tool for parsing Windows registry hives and extracting valuable information for forensic analysis.

0
AppCompatProcessor Logo

A digital forensics tool that extracts and analyzes Windows AppCompat and AmCache registry data for enterprise-scale forensic investigations.

0

Stay Updated with Mandos Brief

Get strategic cybersecurity insights in your inbox