
依存関係ゼロ、USBレスポンダー向けのサブ秒単位のWindowsライブデジタルフォレンジック&インシデントレスポンス(DFIR)トリアージエンジン。
依存関係ゼロ、1秒未満で動作するWindowsライブデジタルフォレンジックおよびインシデントレスポンス(DFIR)トリアージエンジン。迅速なUSBレスポンダー向けに設計。
ライブインシデントレスポンスでは、時間とステルス性がすべてです。従来のトリアージスクリプトには重大な脆弱性があります:
dwShareMode)を介してSQLiteのHistoryデータベースをロックするため、ブラウザを強制終了しない限り(揮発性メモリの証拠を破壊することになる)標準的なコレクターはクラッシュまたは失敗します。OmniTriageはこれをクリーンに解決します:100%純粋なPython標準ライブラリ(winreg、sqlite3、ctypes、subprocess、hashlib、struct)のみでゼロから構築されています。pip install不要、外部バイナリ不要、ディスクへのノイズゼロ、1秒未満で実行され、インタラクティブなスタンドアロンのダークモードHTMLレポートと構造化JSONを生成します。
ConsoleHost_history.txt)とヒューリスティックなキーワードフラグ付け(IEX、DownloadString、mimikatz、bypass、vssadmin)。Win+Rダイアログ履歴)。%TEMP%、%APPDATA%、%LOCALAPPDATA%をスキャンして不審なバイナリ(.exe、.dll、、、、、)を検出。OmniTriage/
├── collectors/
│ ├── __init__.py
│ ├── sysinfo.py # OS build, InstallDate/Format date, Uptime (GetTickCount64), RAM
│ ├── execution.py # PowerShell history, RunMRU, UserAssist (ROT13), BAM
│ ├── browser.py # Chrome, Edge, Brave SQLite lock bypass & download records
│ ├── network.py # Wi-Fi SSIDs, USBSTOR device history, active TCP sockets
│ ├── filesystem.py # Executables/scripts in %TEMP%, SHA-256 hashing, Recent .lnk
│ └── persistence.py # Registry Run/RunOnce keys & Startup folder audit
├── reporters/
│ ├── __init__.py
│ ├── json_reporter.py # Normalized JSON serialization
│ └── html_reporter.py # Standalone dark-mode HTML dashboard
├── omnitriage.py # Main CLI orchestrator & banner
├── run_usb_triage.bat # One-click USB rapid response launcher
├── LICENSE # MIT License
└── README.md
git clone https://github.com/prox0959/OmniTriage.git
cd OmniTriage
python omnitriage.py
OmniTriageフォルダをインシデントレスポンス用USBドライブにコピーします。対象マシンに接続したら、以下を実行します:
run_usb_triage.bat
またはコマンドラインから直接:
python omnitriage.py --out D:\Evidence\Case_101
options:
-h, --help show this help message and exit
--out OUT, -o OUT Output directory for reports (default: triage_output)
--quick, -q Quick mode (skips deep file hashing)
--json-only Only produce JSON report
--html-only Only produce interactive HTML dashboard
--no-browser Skip browser history acquisition
--no-fs Skip staging directory filesystem scans
--lang {en,tr} Console output language (default: en)
____ _ _____ _
/ __ \____ ___ ____ (_)__ \_ __(_) __ _ __ _ ___
/ / / / __ `__ \/ __ \/ / / /\/ '__/ / _` |/ _` |/ _ \
/ /_/ / / / / / / / / / / / / | | / / (_| | (_| | __/
\____/_/ /_/ /_/_/ /_/_/ \/ |_|/_/ \__,_|\__, |\___|
|___/
[::] OmniTriage v1.0.0 | Pure Python DFIR Live Triage Engine
[::] Author: Çınar (prox0959) | Zero External Dependencies
[*] Starting live forensic acquisition on target system...
[*] Destination: C:\Forensics\Case_01
[*] Acquiring OS telemetry, InstallDate, and Uptime...
[+] Host: DESKTOP-IR01 | User: analyst
[+] OS: Windows 10 Home (Build: 26200.9457)
[+] Windows Format/Install Date: 2026-07-03 16:31:44
[+] System Uptime: 0d 6h 52m (Boot: 2026-09-24 17:29:51)
[*] Collecting program execution evidence (PowerShell, RunMRU, UserAssist)...
[+] PowerShell history: 89 commands (0 flagged)
[+] RunMRU (Win+R history): 2 items
[+] UserAssist GUI applications: 100 items decoded
[*] Bypassing SQLite locks & harvesting browser history...
[+] Browser activity: 300 URLs, 19 downloads acquired
[*] Harvesting Wi-Fi profiles, USB connection history, and active sockets...
[+] Wi-Fi & Network Profiles: 2 profiles discovered
[+] Historical USB storage devices: 3 drives logged
[+] Active TCP sockets: 139 connections
[*] Scanning staging directories (%TEMP%, %APPDATA%) for suspicious executables...
[+] Executables in %TEMP%: 40 found
[+] Recent shortcut items: 40 items
[*] Auditing autostart persistence mechanisms (Run/RunOnce, Startup)...
[+] Registry Run/RunOnce keys: 20 entries
[+] Startup folder items: 4 files
[*] Compiling forensic reports...
[+] JSON Report written: C:\Forensics\Case_01\Triage_DESKTOP-IR01_20260925_002236.json (193.21 KB)
[+] HTML Dashboard written: C:\Forensics\Case_01\Triage_DESKTOP-IR01_20260925_002236.html (88.56 KB)
=================================================================
[+] Forensic acquisition completed in 0.24 seconds.
=================================================================
本ソフトウェアは、許可されたデジタルフォレンジック、インシデントレスポンス、システム監査、および教育研究のために厳密に開発されています。あらゆるコンピュータシステム上でアーティファクトを取得する前に、必ず適切な許可と同意を得てください。
.bat.ps1.vbs.js.scr.lnkショートカットアクティビティの追跡。USBSTOR経由でベンダー、プロダクトID、シリアル番号)。HKCUおよびHKLMのRunおよびRunOnce自動起動キーを監査。Startupディレクトリを検査。ipconfig /displaydns)を取得し、アクティブなCommand & Controlインフラ(例:ngrok、duckdns、pastebin、discord webhooks)を検出。fDenyTSConnections)とターミナルサービスのログオンセッション(イベントID 21/24/25)を監査。IEX、DownloadString、mimikatz、encodedcommand)を検出。10ts構造)を直接解析。削除されたマルウェア実行ファイルの過去のパスを明らかにします!schtasks)を監査し、%TEMP%、%APPDATA%、またはUsers\Publicから実行される不審な自動トリガーを検出。Triage_<HOST>_<TIMESTAMP>.html)。Triage_<HOST>_<TIMESTAMP>.json)。| MITRE ATT&CK ID | 戦術 | 技術 | OmniTriageコレクター |
|---|
| T1059.001 | Execution | PowerShellコマンド履歴とScriptBlock | execution.py, remote_exec.py |
| T1021 | Lateral Movement | リモートサービス(RDP、WinRM) | collectors/remote_exec.py |
| T1071.004 | Command & Control | DNSドメイン解決 | collectors/dns_cache.py |
| T1204 | Execution | ユーザー実行(RunMRU / UserAssist / ShimCache) | execution.py, shimcache.py |
| T1053.005 | Persistence | スケジュールタスクの永続化 | collectors/tasks.py |
| T1070 | Anti-Forensics | ホスト上のインジケーター削除(ログ消去) | collectors/event_logs.py |
| T1543.003 | Persistence | Windowsサービス作成(イベント7045) | collectors/event_logs.py |
| T1036 | Defense Evasion | %TEMP% / %APPDATA%でのマスカレーディング | collectors/filesystem.py |
| T1547.001 | Persistence | レジストリRunキー / スタートアップフォルダ | collectors/persistence.py |
| T1082 | Discovery | システム情報とInstallDate | collectors/sysinfo.py |
| T1049 | Discovery | システムネットワーク接続とWi-Fi | collectors/network.py |
| T1005 | Collection | ブラウザデータとダウンロードログ | collectors/browser.py |
| T1005 | Collection | ブラウザデータとダウンロードログ | collectors/browser.py |