Every incident response engagement starts with the same problem: getting the right data off a system, fast, and turning it into something you can actually read. On this page we share the tools we and our clients use for that: small, focused utilities that collect digital evidence and parse the artifacts it contains.
All of them are free and open, and most are command-line tools that fit into scripted, large-scale collection just as well as into a single live-response session.
Triage collection#
Triage is a small set of data that is usually enough to analyse a system, and in most cases it is a reasonable alternative to a full disk image. Standard solutions are not a fit for every environment though. Old operating system versions, limited access windows or restricted tooling all get in the way. In those cases the collectors below may be the working solution.
Parsers#
Collection is only half of the work. The parsers below turn individual Windows artifacts into structured output, usually JSON or CSV, that can be fed into a timeline, a detection pipeline or plain grep.
.evtx) files. Supports JSON output and batch processing, which makes it a good fit for automation, timeline creation and event correlation.$Secure:$SDS stream of the NTFS file system, exposing historical security descriptors. Enables the analysis of permission changes and access control lists.$I files in the Windows Recycle Bin, such as original path, deletion time and the user behind it, which is useful for recovering information about deleted files.certutil tool. Useful for uncovering certificate-related operations and remote resource access.Amcache.hve registry hives to identify evidence of execution and suspicious executables, with optional VirusTotal and OpenTIP lookups for threat intelligence context.NTUSER.DAT files, decodes UserAssist entries and reports the user, the executed application, run count, last run time, focus count and focus time.Suggest a tool#
Do you maintain or use a collector or parser that earned its place in your investigations? Tell us about it at info @ purpleshift.io and we will look at adding it to this page.
Disclaimer: the tools listed here are developed and maintained by their respective authors, not by Purpleshift. We share them because we find them useful in practice. Review and test any of them before running it in a production or evidentiary context.
