diff --git a/README.md b/README.md index 06a752e..cf8fc18 100644 --- a/README.md +++ b/README.md @@ -434,6 +434,8 @@ the [browser malware](#browser-malware) section.* ## Windows Artifacts +* [AChoir](https://github.com/OMENScan/AChoir) - A live incident response + script for gathering Windows artifacts. * [python-evt](https://github.com/williballenthin/python-evt) - Python library for parsing Windows Event Logs. * [python-registry](http://www.williballenthin.com/registry/) - Python