DFIR-ORC / dfir-orc

Forensics artefact collection tool for systems running Microsoft Windows
https://dfir-orc.github.io
GNU Lesser General Public License v2.1
389 stars 42 forks source link

Feature request - GetThis not signed binary file by Microsoft #20

Open tazrome opened 4 years ago

tazrome commented 4 years ago

Hi,

Is it possible to configure GetThis to catch only files that are not signed by Microsoft ? I think, this could be usefull in directories like %WINDIR%... or Program Files...

If it could be interresting, maybe a feature more complete to deal with signed binaries (whitelisting on known unsigned binaries, regexp on signature 's issuer ...) ?

Thank for your work

Regards