fox-it / acquire

acquire is a tool to quickly gather forensic artifacts from disk images or a live system into a lightweight container.
GNU Affero General Public License v3.0
91 stars 26 forks source link

Collect `$Secure:$SII` NTFS file #180

Open Schamper opened 5 months ago

Schamper commented 5 months ago

To make security descriptor lookups faster.