Windows Logs Automation
Offline Artifacts Collection
Unix Collector
Velociraptor Offline Agent

Using the KAPE GUI to analyze the artifacts


KAPE Agent Collector



Run modules on the target machine


Remote Collections with KAPE
Building your agent collector



Full disk image
FTK IMAGER
Disk2vhd
chntpwn

Autopsy
TestDisk & PhotoRec




Velociraptor Analysis


Eventx Analysis
chainsaw
Hunting
Shimcache
SRUM
zircolite

Hayabusa

DeepBlueCLI & WELA & APT-Hunter

Manual Analysis with ericzimmerman Tools

Timeline Explorer

EZViewer

Hasher

Dissect
target-shell <PATH_TO_YOUR_IMAGE>
<PATH_TO_YOUR_IMAGE>
Download artifacts from image raw (VMDK, E01, RAW, etc)
Drop all the security logs from Collectors zip files
Yara scan in raw formats
My bundle:
Convert from yara output into CSV

Yara Repositories:
Dissect Tutorials
gKAPE (offline parser)



GRR

References
Last updated