
Rust-आधारित विंडोज फोरेंसिक टूलकिट रीयल-टाइम MFT निगरानी, इवेंट लॉग स्ट्रीमिंग और चैनल गणना के लिए, जो लाइव सिस्टम विश्लेषण और घटना प्रतिक्रिया को सक्षम बनाता है।
विंडोज़ थिंगीज़... लेकिन Rust में
किसी प्रविष्टि के मानों में परिवर्तन देखें।
listen_mft 0.2.0
Matthew Seyer <https://github.com/forensicmatt/RsWindowsThingies>
See the differences in MFT attirbues.
USAGE:
listen_mft.exe [OPTIONS]
FLAGS:
-h, --help Prints help information
-V, --version Prints version information
OPTIONS:
-d, --debug <DEBUG> Debug level to use. [possible values: Off, Error, Warn, Info, Debug, Trace]
-f, --file <FILE> The file to difference.
ईवेंट सुनने का उपकरण आपको विंडोज़ ईवेंट लॉग को वास्तविक समय में देखने की अनुमति देता है।
नोट: ईवेंट लॉग को पकड़ने में एक मिनट लगता है। इसे ठीक करने के लिए मुझे Windows API के अधिक भागों को लागू करने की आवश्यकता है। जब "Waiting for new events..." संदेश प्रकट होता है, तब आप जानते हैं कि यह सक्रिय रूप से सुन रहा है।
listen_events 0.3.0
Matthew Seyer <https://github.com/forensicmatt/RsWindowsThingies>
Event listener written in Rust. Output is JSONL.
This tool queries the available list of channels then creates a XPath
query and uses the Windows API to monitor for events on the applicable
channels. Use the print_channels tool to list available channels and
their configurations.
USAGE:
listen_events.exe [FLAGS] [OPTIONS]
FLAGS:
-h, --help Prints help information
-p, --historical List historical records along with listening to new changes.
-V, --version Prints version information
OPTIONS:
-c, --channel <CHANNEL>... Specific Channel to listen to.
-d, --debug <DEBUG> Debug level to use. [possible values: Off, Error, Warn, Info, Debug, Trace]
--domain <DOMAIN> The domain to which the user account belongs. Optional.
-f, --format <FORMAT> Output format to use. [defaults to jsonl] [possible values: xml, jsonl]
--server <SERVER> The name of the remote computer to connect to.
--sflag <SFLAG> The authentication method to use to authenticate the user when connecting to the
remote computer. [possible values: Default, Negotiate, Kerberos, NTLM]
--user <USER> The user name to use to connect to the remote computer.
print_channels उपकरण आपको चैनल और उनके कॉन्फ़िग्रेशन को डंप करने की अनुमति देता है। इससे आपको अपने सिस्टम पर उपलब्ध चैनलों और उनकी कॉन्फ़िगरेशन सेटिंग्स की पहचान करने में मदद मिलती है। यह मुख्य रूप से उन लाइब्रेरी घटकों के लिए एक इंटरफ़ेस है जो ईवेंट मॉनिटरिंग टूल में निगरानी के लिए चैनल स्थापित करने में सहायता करते हैं।
print_channels 0.2.0
Matthew Seyer <https://github.com/forensicmatt/RsWindowsThingies>
Print Channel Propperties.
USAGE:
print_channels.exe [OPTIONS]
FLAGS:
-h, --help Prints help information
-V, --version Prints version information
OPTIONS:
-d, --debug <DEBUG> Debug level to use. [possible values: Off, Error, Warn, Info, Debug, Trace]
--domain <DOMAIN> The domain to which the user account belongs. Optional.
-f, --format <FORMAT> Output format. (defaults to text) [possible values: text, jsonl]
--server <SERVER> The name of the remote computer to connect to.
--sflag <SFLAG> The authentication method to use to authenticate the user when connecting to the remote
computer. [possible values: Default, Negotiate, Kerberos, NTLM]
--user <USER> The user name to use to connect to the remote computer.
यह एक उदाहरण है कि टेक्स्ट आउटपुट कैसा दिखता है। (आप jsonl में भी प्रिंट कर सकते हैं)
========================================================
Channel: Windows PowerShell
========================================================
EvtChannelConfigAccess: "O:BAG:SYD:(A;;0x2;;;S-1-15-2-1)(A;;0x2;;;S-1-15-3-1024-3153509613-960666767-3724611135-2725662640-12138253-543910227-1950414635-4190290187)(A;;0xf0007;;;SY)(A;;0x7;;;BA)(A;;0x7;;;SO)(A;;0x3;;;IU)(A;;0x3;;;SU)(A;;0x3;;;S-1-5-3)(A;;0x3;;;S-1-5-33)(A;;0x1;;;S-1-5-32-573)"
EvtChannelConfigClassicEventlog: true
EvtChannelConfigEnabled: true
EvtChannelConfigIsolation: 0
EvtChannelConfigOwningPublisher: ""
EvtChannelConfigType: 0
EvtChannelLoggingConfigAutoBackup: false
EvtChannelLoggingConfigLogFilePath: "%SystemRoot%\\System32\\Winevt\\Logs\\Windows PowerShell.evtx"
EvtChannelLoggingConfigMaxSize: 15728640
EvtChannelLoggingConfigRetention: false
EvtChannelPublishingConfigBufferSize: 64
EvtChannelPublishingConfigClockType: 0
EvtChannelPublishingConfigControlGuid: null
EvtChannelPublishingConfigFileMax: 1
EvtChannelPublishingConfigKeywords: null
EvtChannelPublishingConfigLatency: 1000
EvtChannelPublishingConfigLevel: null
EvtChannelPublishingConfigMaxBuffers: 64
EvtChannelPublishingConfigMinBuffers: 0
EvtChannelPublishingConfigSidType: 1
print_publishers उपकरण आपको प्रकाशकों और उनके कॉन्फ़िगरेशन को डंप करने की अनुमति देता है। इससे आपको अपने सिस्टम पर उपलब्ध चैनलों और उनकी कॉन्फ़िगरेशन सेटिंग्स की पहचान करने में मदद मिलती है। यह मुख्य रूप से उन लाइब्रेरी घटकों के लिए एक इंटरफ़ेस है जो निगरानी उद्देश्यों के लिए मौजूद प्रदाताओं को स्थापित करने में सहायता करते हैं।
print_publishers 0.1.0
Matthew Seyer <https://github.com/forensicmatt/RsWindowsThingies>
Print Publisher Propperties.
USAGE:
print_publishers.exe [OPTIONS]
FLAGS:
-h, --help Prints help information
-V, --version Prints version information
OPTIONS:
-d, --debug <DEBUG> Debug level to use. [possible values: Off, Error, Warn, Info, Debug, Trace]
--domain <DOMAIN> The domain to which the user account belongs. Optional.
-f, --format <FORMAT> Output format. (defaults to text) [possible values: text, jsonl]
-p, --provider <PROVIDER>... Specific Provider.
--server <SERVER> The name of the remote computer to connect to.
--sflag <SFLAG> The authentication method to use to authenticate the user when connecting to the
remote computer. [possible values: Default, Negotiate, Kerberos, NTLM]
--user <USER> The user name to use to connect to the remote computer.