Closed nwf9 closed 2 years ago
Hey there,
What do you mean by live command capabilities? To provide support for customization of command parameters for the tools of Eric Zimmerman and possibly others?
Cheers
I mean live response instead of collecting all those artifact.
That would be a new tool entirely that falls out of the scope of batch forensics that this utility was written for. Have a look at https://github.com/google/grr for a live forensics tool.
I’m not talking about an agent but only an improvement of this script to handle the locked files instead of grab something.
Hi Diogo,
Is it possible to update your batch script to include the live command capabilites for Eric Zimmerman tools like MFT,Amcache and so on.