RetrievIR:专为事件响应设计的Windows设备安全取证收集工具
Common Information
Type Value
UUID 3058153b-3e90-4b5a-a1ab-9795b5e11cfa
Fingerprint d6c56cd64394cd60
Analysis status DONE
Considered CTI value 0
Text language
Published June 20, 2024, midnight
Added to db Sept. 1, 2024, 9:41 a.m.
Last updated Nov. 17, 2024, 7:44 p.m.
Headline RetrievIR:专为事件响应设计的Windows设备安全取证收集工具
Title RetrievIR:专为事件响应设计的Windows设备安全取证收集工具
Detected Hints/Tags/Attributes 3/1/12
RSS Feed
Details Id Enabled Feed title Url Added to db
Details 483 CN-SEC 中文网 https://cn-sec.com/feed/ 2024-08-30 22:08
Attributes
Details Type #Events CTI Value
Details Domain 4127
github.com
Details File 2
retrievir.ps1
Details File 153
config.json
Details File 18
targets.txt
Details File 1
my_config.json
Details File 2
parseir.ps1
Details File 1
parsing_config.json
Details File 1
example.json
Details File 1
psscriptrootparsing_config.json
Details Github username 2
joeavanzato
Details Url 1
https://github.com/joeavanzato/retrievir.git
Details Url 1
https://github.com/joeavanzato/retrievir