How to use RetrievIR forensics package to collect forensics via CrowdStrike EDR RTR
Tags
attack-pattern: | Data Powershell - T1059.001 Powershell - T1086 |
Common Information
Type | Value |
---|---|
UUID | a736cbbc-1a06-4f69-85a6-0bfd0c4c2532 |
Fingerprint | 1485bb5642b683cf |
Analysis status | DONE |
Considered CTI value | -2 |
Text language | |
Published | Oct. 31, 2024, 12:23 p.m. |
Added to db | Oct. 31, 2024, 1:46 p.m. |
Last updated | Nov. 17, 2024, 6:31 p.m. |
Headline | How to use RetrievIR forensics package to collect forensics on a windows system |
Title | How to use RetrievIR forensics package to collect forensics via CrowdStrike EDR RTR |
Detected Hints/Tags/Attributes | 12/1/7 |
Source URLs
URL Provider
RSS Feed
Details | Id | Enabled | Feed title | Url | Added to db |
---|---|---|---|---|---|
Details | 167 | ✔ | Cybersecurity on Medium | https://medium.com/feed/tag/cybersecurity | 2024-08-30 22:08 |
Attributes
Details | Type | #Events | CTI | Value |
---|---|---|---|---|
Details | File | 2 | retrievir.ps1 |
|
Details | File | 153 | config.json |
|
Details | File | 1 | c:\my_config.json |
|
Details | File | 1 | c:\users\user\downloads\retrievir-release_1_1\retrievir-release_1_1\ command ran c:\users\user\downloads\retrievir-release_1_1\retrievir-release_1_1\retrievir.ps1 |
|
Details | File | 2 | parseir.ps1 |
|
Details | File | 1 | c:\users\user\downloads\retrievir-release_1_1\retrievir-release_1_1\parseir.ps1 |
|
Details | File | 1 | c:\users\user\downloads\retrievir-release_1_1\retrievir-release_1_1\parsing_config.json |