ir-rescue
ir-rescue copied to clipboard
A Windows Batch script and a Unix Bash script to comprehensively collect host forensic data during incident response.
Added the following extractions: - installed software - shellbags - extraction of NTUSER and UsrClass log files
Hi diogo-fernan, First of all, Thank for your great tool. Secondly, I would like to request 2 new features in this script is export Window Event Powershell and CSV Format....
Hi Diogo, Use memtriage to grab all the relevant info without dumping memory.
Hello, **For the windows version** I think there is a problem with the autoruns.exe (see screenshot) Also for the web browser history, instead of : `"%BHV% /HistorySource 1 /VisitTimeFilterType 1...