Triage Media
Recently, I had a need to quickly collect some files of interest from a hard drive. I had limited time and I was really not concerned with deleted data, only logical files that existed. I manually created a LEF with the areas that interested me, but I then began to think about those areas where people are most likely going to collect artifacts from in a quick triage process.
I came up with (5) five distinct areas on a volume:
User profiles (\Documents & Settings or \Users)
Recycle Bin
System Volume Information
Registry (\Windows\System32\Config)
Program Files
So I built a triage EnScript that contains options to collect data from each of these areas in an automated way.
My purpose of writing this was to have a relatively quick automated way to collect user data from any attached/previewed media and then have that data placed into a logical evidence file in a logical manner that made sense later if I collected data from several pieces of media.
The help button explains each of the options:
Running the EnScript with each of the options will result in up to (6) six LEF files being created for each volume, one for each option, depending on whether that path is present. You can then examine those LEF files as time permits. Obviously the time to process each option is dependant on the amount of data that may or may not be in a specific area.
Download Here
1 comments:
Great idea. Thanks, Lance.
I could have used this a month ago. When I arrived on scene to image a drive I was faced with a new, 1 TB drive in a home pc. Neither I nor the attorneys expected that and I wasn't allowed to stay long enough to get the entire drive. I ended up doing what you suggest and also getting as much UA as time allowed.
Post a Comment