How to use RetrievIR forensics package to collect forensics via CrowdStrike EDR RTR
Common Information
Type Value
UUID a736cbbc-1a06-4f69-85a6-0bfd0c4c2532
Fingerprint 1485bb5642b683cf
Analysis status DONE
Considered CTI value -2
Text language
Published Oct. 31, 2024, 12:23 p.m.
Added to db Oct. 31, 2024, 1:46 p.m.
Last updated Nov. 17, 2024, 6:31 p.m.
Headline How to use RetrievIR forensics package to collect forensics on a windows system
Title How to use RetrievIR forensics package to collect forensics via CrowdStrike EDR RTR
Detected Hints/Tags/Attributes 12/1/7
RSS Feed
Details Id Enabled Feed title Url Added to db
Details 167 Cybersecurity on Medium https://medium.com/feed/tag/cybersecurity 2024-08-30 22:08
Attributes
Details Type #Events CTI Value
Details File 2
retrievir.ps1
Details File 153
config.json
Details File 1
c:\my_config.json
Details File 1
c:\users\user\downloads\retrievir-release_1_1\retrievir-release_1_1\ command ran  c:\users\user\downloads\retrievir-release_1_1\retrievir-release_1_1\retrievir.ps1
Details File 2
parseir.ps1
Details File 1
c:\users\user\downloads\retrievir-release_1_1\retrievir-release_1_1\parseir.ps1
Details File 1
c:\users\user\downloads\retrievir-release_1_1\retrievir-release_1_1\parsing_config.json