-
srum-dump
A forensics tool to convert the data in the Windows srum (System Resource Usage Monitor) database to an xlsx spreadsheet.
-
InfluxDB
Power Real-Time Data Analytics at Scale. Get real-time insights from all types of time series data with InfluxDB. Ingest, query, and analyze billions of data points in real-time with unbounded cardinality.
-
SaaSHub
SaaSHub - Software Alternatives and Reviews. SaaSHub helps you find the best software and product alternatives
Use yarp. It includes a module to access hives on a live system.
FGET can get the locked files for you. https://github.com/MarkBaggett/srum-dump/blob/master/FGET.exe
However, what you are trying to do has already been done. For collections look at velociraptor's offline collector https://github.com/Velocidex/velociraptor. For processing check out Log2Timeline (plaso) https://github.com/log2timeline/plaso.
However, what you are trying to do has already been done. For collections look at velociraptor's offline collector https://github.com/Velocidex/velociraptor. For processing check out Log2Timeline (plaso) https://github.com/log2timeline/plaso.
Want to put those processed plaso files in an elasticsearch instance check out Timesketch - https://github.com/google/timesketch.
Related posts
-
I feel like I'm putting the cart before the horse. Noob question.
-
Solving a child porn case (student environment)
-
How to carry out mass Digital Forensic Collections using open source tools?
-
NSO Group iPhone Zero-Click, Zero-Day Exploit Captured in the Wild
-
Windows, macOS, Linux vulnerability Scanner or Script