沒錯!資源收集完之後呢!為了後續的圖形化或是易於識別,就是要轉檔啦!
將其資源以及開源工具對照後,以程式將其進行自動化轉檔,以加速分析時效:
| 資源 | 工具 | 作者/套件 | 
|---|---|---|
| Registry | Amcache.hve | Registry Explorer | 
| AmcacheParser | RegRipper3.0 | EricZimmerman & keydet89 | 
| Bitmap Cache | bmc-tools | ANSSI-FR | 
| Browser History | BrowsingHistoryView | NirSoft | 
| Event Log | Event Log Explorer | FSPro Labs | 
| Jump Lists | JumpListsView | NirSoft | 
| Memory | Volatility3 | Volatility Foundation | 
| MFT | MFTECmd | EricZimmerman | 
| Prefetch | PrefetchView | NirSoft | 
| RDP Cache | Regedit | NirSoft | 
| SRUM | SrumECmd | EricZimmerman | 
| WMI | WMI Explorer | SAPIEN PRTG |