AChoir

Artifact Collector

A scripting framework to simplify the process of gathering forensic artifacts from Windows devices.

Windows Live Artifacts Acquisition Script

GitHub

184 stars
13 watching
29 forks
Language: C++
last commit: over 2 years ago
Linked from 2 awesome lists


Backlinks from these awesome lists:

Related projects:

Repository Description Stars
omenscan/achoirx A Go-based forensic collection and analysis tool designed for cross-platform use. 37
forensicanalysis/artifactcollector A tool to extract forensic artifacts from various operating systems 271
ownsecurity/fastir_artifacts A tool for collecting forensic artifacts from live hosts across multiple operating systems. 160
abdulrhmanalfaifi/fennec Tool for collecting artifacts from *nix systems during incident response 195
forensicartifacts/artifacts A repository of machine-readable digital forensic artifacts in YAML format, validated by Python code. 1,071
fox-it/acquire A tool for gathering forensic artifacts from disk images or live systems into a lightweight container. 92
muteb/hoarder A tool to collect and parse Windows artifacts from disk images or live machines. 194
silv3rhorn/artifactextractor Extracts Windows artifacts from images and virtual machines 66
pstirparo/mac4n6 A centralized collection of forensics artifacts locations for Mac OS X and iOS. 326
orlikoski/cylr A tool that collects and preserves forensic artifacts from NTFS file systems without impacting the host system. 652
sekoialab/fastir_collector A tool for collecting and analyzing Windows system artefacts on live systems 507
ydkhatri/macforensics A collection of scripts to analyze and process macOS forensic artifacts. 182
op7ic/unix_collector A script designed to automatically collect various system artifacts and data from Unix-like systems without the need for manual intervention or external dependencies. 33
gems-uff/noworkflow Automates the tracking of how data is produced and transformed in scientific experiments. 122
tclahr/uac Automates incident response data collection from various operating systems 824