
Digital forensic acquisition tool for Windows based incident response.
Digital forensic acquisition tool for Windows-based incident response.
To run, drop dfirtriage.exe on the target or connected USB drive and execute with admin rights, -h for help.
This document outlines the functionality and proper use of the DFIRtriage tool. Also included is detailed information to help with analysis of the output. The goal is to equip the Incident Responder with the tools needed to gather and analyze data quickly.
DFIRtriage is an incident response tool designed to provide the Incident Responder with rapid host data. Upon execution, select host data and information will be gathered and placed into the execution directory. DFIRtriage may be ran from a USB drive or executed remotely on the target host.
Output restructure
Logging total run time
Bug fixes
Added arguments for individual system artifacts
-sdb, --srumdb (srum database), -hf, --hiberfil (hiberfil.sys), -p, --pagefile (pagefile.sys)Improved executable file hashing capabilites
Running process details
Bitlocker key dump
-bl or --bitlocker argument on the command lineMemory acquisition no longer default action
-m or --memory argument on the command lineUser prompt removed from end of execution
-hl or --headless argument to bypass the ending user prompt, script will run to completion, clean up, and exit with no user intervention.Windows firewall
-elf argumentImproved user account report
dtfind - admin requirement removed
3rd party tools update
External IP
PowerShell
-elf, --evtlogfiles argumentSystem Information
Event Logs
-elf, --evtlogfiles argumentApplication event log
Security event log
Powershell event log
Windows Firewall event log
Local Modifications (Levels 0, 2, 4) (2004, 2005, 2006, 2009, 2033)
The tool repository contains the full toolset required for proper execution and is packed into a single a single file named core.ir. This .ir file is the only required dependency of DFIRtriage when running in Python and should reside in a directory named data, (ie. ./data/core.ir). The compiled version of DFIRtriage has the full toolset embedded and does not require the addition of the ./data/core.ir file.
DFIRtriage acquires data from the host on which it is executed. Behind the keyboard executions are best conducted from a USB device. For acquisitions of remote hosts, the DFIRtriage files will need to be copied to the target, then executed via remote shell. (ie. SSH or PSEXEC)
WARNING: Do not use PSEXEC arguments to pass credentials to a remote system for authentication. Doing so will send your username and password across the network in the clear.
The following steps should be taken for proper usage of PSEXEC
You can used this mapped connection to copy DFIRtriage to the target.
We can now shovel a remote shell to the target host using PSEXEC.
psexec \\target\_host cmd
You now have a remote shell on the target. All commands executed at this point are done so on the target host.
Usage
Once the remote shell has been established on the target you can change directory to the location of the extracted DFIRtriage.exe file and execute.
Memory acquisition does not occur by default. To dump memory, pass the following argument: -m, --memory
DFIRtriage must be executed with Administrative privileges.
Once complete, press enter to cleanup the output directory. If running the executable, the only data remaining with be a zipped archive of the output as well as DFIRtriage.exe. If running the Python code directly only DFIRtriage python script and a zipped archive of the output are left.
The output folder name includes the target hostname and a date/time code indicating when DFIRtriage was executed. The date/time code format is YYYYMMDDHHMMSS.
The table below provides a general listing of the type of information and artifacts gathered by DFIRtriage v6.0.