Git Product home page Git Product logo

csirt-collect's Introduction

CSIRT-Collect

A set of PowerShell scripts to collect memory and (triage) disk forensics for incident response investigations.

The default script leverages a network share, from which it will access and copy the required executables and subsequently upload the acquired evidence to the same share post-collection.

Permission requirements for said directory will be dependent on the nuances of the environment and what credentials are used for the script execution (interactive vs. automation)

In the demonstration code, a network location of \\Synology\Collections can be seen. This should be changed to reflect the specifics of your environment.

Collections folder needs to include:

  • subdirectory KAPE; copy the directory from existing install
  • subdirectory MEMORY; 7za.exe command line version of 7zip and Magnet RAM Capture.

For a walkthough of the script https://bakerstreetforensics.com/2021/12/13/adding-ram-collections-to-kape-triage/

CSIRT-Collect

  • Maps to existing network drive -
    • Subdir 1: “Memory” – Winpmem and 7-Zip executables
    • Subdir 2: ”KAPE” – directory (copied from local install)
  • Creates a local directory on asset
  • Copies the Memory exe files to local directory
  • Captures memory with Magnet RAM Capture
  • When complete, ZIPs the memory image
  • Renames the zip file based on hostname
  • Documents the OS Build Info (no need to determine profile for Volatility)
  • Compressed image is copied to network directory and deleted from host after transfer complete
  • New temp Directory on asset for KAPE output
  • KAPE KapeTriage collection is run using VHDX as output format [$hostname.vhdx]
  • VHDX transfers to network
  • Removes the local KAPE directory after completion
  • Writes a “Process complete” text file to network to signal investigators that collection is ready for analysis

CSIRT-Collect_USB

This script will:

  • capture a memory image with Magnet Ram Capture,
  • capture a triage image with KAPE,
  • check for encrypted disks,
  • recover the active BitLocker Recovery key, all directly to the USB device.

Prerequisites:

On the root of the USB:

  • CSIRT-Collect_USB.ps1
  • folder (empty to start) titled 'Collections'
  • KAPE folder from default install. Ensure you have EDDv300.exe in \modules\bin\EDD
  • MEMORY folder with MRC.exe and 7za.exe inside

Execution:

  • Open PowerShell as Adminstrator
  • Navigate to the USB device
  • Execute ./CSIRT-Collect_USB.ps1

For a walkthrough of the USB version https://bakerstreetforensics.com/2021/12/17/csirt-collect-usb/

csirt-collect's People

Contributors

dwmetz avatar stark4n6 avatar andrewrathbun avatar

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.