ir-rescue icon indicating copy to clipboard operation
ir-rescue copied to clipboard

A Windows Batch script and a Unix Bash script to comprehensively collect host forensic data during incident response.

Results 4 ir-rescue issues
Sort by recently updated
recently updated
newest added

Added the following extractions: - installed software - shellbags - extraction of NTUSER and UsrClass log files

enhancement

Hi diogo-fernan, First of all, Thank for your great tool. Secondly, I would like to request 2 new features in this script is export Window Event Powershell and CSV Format....

Hi Diogo, Use memtriage to grab all the relevant info without dumping memory.

enhancement

Hello, **For the windows version** I think there is a problem with the autoruns.exe (see screenshot) Also for the web browser history, instead of : `"%BHV% /HistorySource 1 /VisitTimeFilterType 1...