GithubHelp home page GithubHelp logo

panoptcy / dfir-art-collector Goto Github PK

View Code? Open in Web Editor NEW
0.0 1.0 0.0 1.95 MB

A collection of scripts and tools to automate digital forensics and incident response evidence collection

Batchfile 100.00%

dfir-art-collector's Introduction

DFIR ART COLLECTOR

DFIR ART COLLECTOR or Digtial Forensics and Incident Response ARTifact COLLECTOR is a collection of scripts and tools that automate the collection of useful artifacts for digital forensics and incident response work. DFIR ART COLLECTOR starts by pulling the most volatile evidence first then produces down to less volatile artifacts until finally creating a disk image using FTK Imager. For more information on DFIR ART COLLECTOR please see my blog.

Install

Due to licensing concerns two tools are omited from this repo, they are the commandline version of AccessData's FTK Iamger and Microsoft's Sysinternals. For the scripts to work correctly, please download Microsoft's Sysinternal Suite and extract all the tools into the tools\win\SysinternalsSuite directory. If you also wish to collect the raw drive image you will also need to download the commandline version of AccessData's FTK Iamger and extract the files to the tools\win\access_data directory.

Usage

To run DFIR ART COLLECTOR you simply need to run the batch script as an administrator from the commandline with the following arguments:

dfir-art-collector.bat [path\to\the\tools\directory] [path\to\store\evidence] [drive_number_to_image]

For more information on usage please see my blog.

Change Log

2017-12-5 Uploaded version 1.0.0

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.