mbevilacqua / appcompatprocessor

"Evolving AppCompat/AmCache data analysis beyond grep"
Apache License 2.0
197 stars 25 forks source link

Audit scripts #11

Closed mgreen27 closed 6 years ago

mgreen27 commented 6 years ago

Hello,

Wondering if you can share the Redline/MIR audit scripts for collecting information for your tool in the repository?

Matt

mbevilacqua commented 6 years ago

RedLine is freely available at FireEye / Mandiant's website. That being said, it's probably overkill to simply grab ShimCache or AmCache. I suggest automating the process with powershell or GPO's if an EDR solution is not available.

mgreen27 commented 6 years ago

Thank you for the reply. I am actually planning a collection via MIR. From your documentation I wasnt sure what the LUA in "AppCompat Mir LUA script (XML)" was so thought I would reach out.

mbevilacqua commented 6 years ago

That's a Mandiant script to acquire ShimCache using Mir but I don't think it's available to the general public. If using Mir you can simply create a RegistryAudit to pull in the registry values where ShimCache data is stored (all controlsets recommended, + RegBack) and ACP will also happily ingest that for you through the appcompat_mirregistryaudit ingest module.

mgreen27 commented 6 years ago

Ahh makes sense. Thank you!

mbevilacqua commented 6 years ago

Perfect! Since you're a Mir user you can also reach out through your FireEye point of contact and get that routed my way. I should be able to better support you from there and even send over a sample audit of what you're looking for to make the acquisition as fast as possible with Mir.