Open randomaccess3 opened 6 years ago
Recycle bin parser completed.
Event log parser complete!
- I'm working on a SQLECmd map for this. I'll add 3 to my list too.
Let me know if you need anything else or want any adjustments made.
Having not used sqlecmd at all, thoughts on adding it to ezparser and running all the relevant maps? That being said, stickies and notifications arent part of the basic collection....maybe i need an advanced collection?
Having not used sqlecmd at all, thoughts on adding it to ezparser and running all the relevant maps? That being said, stickies and notifications arent part of the basic collection....maybe i need an advanced collection?
That is 100% the plan to add it. I want to flesh out the browser stuff before it's added. I'm slowly chipping away at more Maps to make the tool more "relevant" out of the box for those who may run only KAPETriage, BasicCollection, or SANSTriage.
Maybe there's room for a SQL databases Compound target? One that'll just have stuff SQLECmd parses all that is grabbed?
yeah that might be the way to go, but then it's a matter of people knowing what they should collect. I'm thinking I will go about the more advanced collection one; i tend to tick a bunch of other boxes ontop of basic all the time anyways and that list is growing so would be worthwhile. Will start jotting down some ideas
Would AdvancedCollection call Basic and then just point to other Targets beyond that? Or are you thinking something else?
Maybe it's a good opportunity to take a look at Basic and verify the contents of it fitting the basic label and saving the more advanced stuff for Advanced?
Yep. Nah Basic is "If I had a choice of collecting as much as I could in an intrusion regardless of OS, what would I go for", which at the time was everything there listed. It could be expanded to add other stuff, but I've left that to the user. That being said, one shot on a box im ticking email and web browsers, which increase acquisition time a lot, especially if VSS is ticked.
File Format Viewers!
Figured I'd put the requests in.