acquire icon indicating copy to clipboard operation
acquire copied to clipboard

Add Atera/Splashtop to Acquire

Open DissectBot opened this issue 1 year ago • 0 comments

During a CERT case it was observed that the actors were using the Atera Management Agent. This agent seems to use the Splashtop Remote Access Tool underlying. We'll need to add these locations to acquire so we can query this data with target-query.

File locations: C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\log\

  • svcinfo.txt -> Splashtop service information loggin;
  • agent_log.txt -> agent output, generic information;
  • sysinfo.txt -> information about server and session startups;
  • SPLog.00x -> information about clipboard, transferred files, etc;

DissectBot avatar Mar 14 '24 16:03 DissectBot