Update bat for live parsing
nwf9 opened this issue · 4 comments
nwf9 commented
Hi Diogo,
Is it possible to update your batch script to include the live command capabilites for Eric Zimmerman tools like MFT,Amcache and so on.
diogo-fernan commented
Hey there,
What do you mean by live command capabilities? To provide support for customization of command parameters for the tools of Eric Zimmerman and possibly others?
Cheers
nwf9 commented
I mean live response instead of collecting all those artifact.
diogo-fernan commented
That would be a new tool entirely that falls out of the scope of batch forensics that this utility was written for. Have a look at https://github.com/google/grr for a live forensics tool.
nwf9 commented
I’m not talking about an agent but only an improvement of this script to handle the locked files instead of grab something.