Updating dead RegRipper Link

This commit is contained in:
Explie 2020-10-28 13:52:14 +01:00 committed by GitHub
parent 6a69cc8d88
commit f925159070
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

View File

@ -251,5 +251,5 @@ Digital Forensics and Incident Response (DFIR) teams are groups of people in an
* [Panorama](https://github.com/AlmCo/Panorama) - Fast incident overview on live Windows systems. * [Panorama](https://github.com/AlmCo/Panorama) - Fast incident overview on live Windows systems.
* [PowerForensics](https://github.com/Invoke-IR/PowerForensics) - Live disk forensics platform, using PowerShell. * [PowerForensics](https://github.com/Invoke-IR/PowerForensics) - Live disk forensics platform, using PowerShell.
* [PSRecon](https://github.com/gfoss/PSRecon/) - PSRecon gathers data from a remote Windows host using PowerShell (v2 or later), organizes the data into folders, hashes all extracted data, hashes PowerShell and various system properties, and sends the data off to the security team. The data can be pushed to a share, sent over email, or retained locally. * [PSRecon](https://github.com/gfoss/PSRecon/) - PSRecon gathers data from a remote Windows host using PowerShell (v2 or later), organizes the data into folders, hashes all extracted data, hashes PowerShell and various system properties, and sends the data off to the security team. The data can be pushed to a share, sent over email, or retained locally.
* [RegRipper](https://code.google.com/p/regripper/wiki/RegRipper) - Open source tool, written in Perl, for extracting/parsing information (keys, values, data) from the Registry and presenting it for analysis. * [RegRipper](https://github.com/keydet89/RegRipper3.0) - Open source tool, written in Perl, for extracting/parsing information (keys, values, data) from the Registry and presenting it for analysis.
* [TRIAGE-IR](https://code.google.com/p/triage-ir/) - IR collector for Windows. * [TRIAGE-IR](https://code.google.com/p/triage-ir/) - IR collector for Windows.