AdvancedIPScanner

Appsv1.1

Author: Reece394

description

Advanced IP Scanner Artifacts

paths

29 paths
paths use Windows environment syntax

collection commands

# PowerShell Artifact Collection Script
# Target: AdvancedIPScanner
# Run as Administrator

#Requires -RunAsAdministrator

$ErrorActionPreference = "SilentlyContinue"
$DestBase = "D:\Evidence"

# Function to handle artifact collection with robocopy
function Collect-Artifact {
    param (
        [string]$SourceDir,
        [string]$FolderName,
        [string]$FileMask = "*"
    )
    $FullDest = Join-Path -Path $DestBase -ChildPath $FolderName
    robocopy "$SourceDir" "$FullDest" "$FileMask" /E /COPY:DAT /R:0 /W:0 /NP /NFL /NDL /NJH /NJS | Out-Null
}

# 1. Advanced IP Scanner Aliases - User Folder
$UserPath = Join-Path $env:USERPROFILE ""
Collect-Artifact -SourceDir "$UserPath" -FileMask "advanced_ip_scanner_Aliases.bin" -FolderName "Advanced_IP_Scanner_Aliases___User_Folder"

# 2. Advanced IP Scanner Aliases - User Temp Folder
$UserPath = Join-Path $env:USERPROFILE "AppData\Local\Temp\Advanced IP Scanner 2"
Collect-Artifact -SourceDir "$UserPath" -FileMask "advanced_ip_scanner_Aliases.bin" -FolderName "Advanced_IP_Scanner_Aliases___User_Temp_Folder"

# 3. Advanced IP Scanner Aliases - Windows Temp Folder
Collect-Artifact -SourceDir "C:\Windows\Temp\Advanced IP Scanner 2" -FileMask "advanced_ip_scanner_Aliases.bin" -FolderName "Advanced_IP_Scanner_Aliases___Windows_Temp_Folder"

# 4. Advanced IP Scanner Aliases - SYSTEM SysWOW64 User Folder
Collect-Artifact -SourceDir "C:\Windows\SysWOW64\config\systemprofile" -FileMask "advanced_ip_scanner_Aliases.bin" -FolderName "Advanced_IP_Scanner_Aliases___SYSTEM_SysWOW64_User_Folder"

# 5. Advanced IP Scanner Aliases - SYSTEM User Folder
Collect-Artifact -SourceDir "C:\Windows\System32\config\systemprofile" -FileMask "advanced_ip_scanner_Aliases.bin" -FolderName "Advanced_IP_Scanner_Aliases___SYSTEM_User_Folder"

# 6. Advanced IP Scanner Aliases - LocalService User Folder
Collect-Artifact -SourceDir "C:\Windows\ServiceProfiles\LocalService" -FileMask "advanced_ip_scanner_Aliases.bin" -FolderName "Advanced_IP_Scanner_Aliases___LocalService_User_Folder"

# 7. Advanced IP Scanner Aliases - NetworkService User Folder
Collect-Artifact -SourceDir "C:\Windows\ServiceProfiles\NetworkService" -FileMask "advanced_ip_scanner_Aliases.bin" -FolderName "Advanced_IP_Scanner_Aliases___NetworkService_User_Folder"

# 8. Advanced IP Scanner Comments - User Folder
$UserPath = Join-Path $env:USERPROFILE ""
Collect-Artifact -SourceDir "$UserPath" -FileMask "advanced_ip_scanner_Comments.bin" -FolderName "Advanced_IP_Scanner_Comments___User_Folder"

# 9. Advanced IP Scanner Comments - User Temp Folder
$UserPath = Join-Path $env:USERPROFILE "AppData\Local\Temp\Advanced IP Scanner 2"
Collect-Artifact -SourceDir "$UserPath" -FileMask "advanced_ip_scanner_Comments.bin" -FolderName "Advanced_IP_Scanner_Comments___User_Temp_Folder"

# 10. Advanced IP Scanner Comments - Windows Temp Folder
Collect-Artifact -SourceDir "C:\Windows\Temp\Advanced IP Scanner 2" -FileMask "advanced_ip_scanner_Comments.bin" -FolderName "Advanced_IP_Scanner_Comments___Windows_Temp_Folder"

# 11. Advanced IP Scanner Comments - SYSTEM SysWOW64 User Folder
Collect-Artifact -SourceDir "C:\Windows\SysWOW64\config\systemprofile" -FileMask "advanced_ip_scanner_Comments.bin" -FolderName "Advanced_IP_Scanner_Comments___SYSTEM_SysWOW64_User_Folder"

# 12. Advanced IP Scanner Comments - SYSTEM User Folder
Collect-Artifact -SourceDir "C:\Windows\System32\config\systemprofile" -FileMask "advanced_ip_scanner_Comments.bin" -FolderName "Advanced_IP_Scanner_Comments___SYSTEM_User_Folder"

# 13. Advanced IP Scanner Comments - LocalService User Folder
Collect-Artifact -SourceDir "C:\Windows\ServiceProfiles\LocalService" -FileMask "advanced_ip_scanner_Comments.bin" -FolderName "Advanced_IP_Scanner_Comments___LocalService_User_Folder"

# 14. Advanced IP Scanner Comments - NetworkService User Folder
Collect-Artifact -SourceDir "C:\Windows\ServiceProfiles\NetworkService" -FileMask "advanced_ip_scanner_Comments.bin" -FolderName "Advanced_IP_Scanner_Comments___NetworkService_User_Folder"

# 15. Advanced IP Scanner MAC - User Folder
$UserPath = Join-Path $env:USERPROFILE ""
Collect-Artifact -SourceDir "$UserPath" -FileMask "advanced_ip_scanner_MAC.bin" -FolderName "Advanced_IP_Scanner_MAC___User_Folder"

# 16. Advanced IP Scanner MAC - User Temp Folder
$UserPath = Join-Path $env:USERPROFILE "AppData\Local\Temp\Advanced IP Scanner 2"
Collect-Artifact -SourceDir "$UserPath" -FileMask "advanced_ip_scanner_MAC.bin" -FolderName "Advanced_IP_Scanner_MAC___User_Temp_Folder"

# 17. Advanced IP Scanner MAC - Windows Temp Folder
Collect-Artifact -SourceDir "C:\Windows\Temp\Advanced IP Scanner 2" -FileMask "advanced_ip_scanner_MAC.bin" -FolderName "Advanced_IP_Scanner_MAC___Windows_Temp_Folder"

# 18. Advanced IP Scanner MAC - SYSTEM SysWOW64 User Folder
Collect-Artifact -SourceDir "C:\Windows\SysWOW64\config\systemprofile" -FileMask "advanced_ip_scanner_MAC.bin" -FolderName "Advanced_IP_Scanner_MAC___SYSTEM_SysWOW64_User_Folder"

# 19. Advanced IP Scanner MAC - SYSTEM User Folder
Collect-Artifact -SourceDir "C:\Windows\System32\config\systemprofile" -FileMask "advanced_ip_scanner_MAC.bin" -FolderName "Advanced_IP_Scanner_MAC___SYSTEM_User_Folder"

# 20. Advanced IP Scanner MAC - LocalService User Folder
Collect-Artifact -SourceDir "C:\Windows\ServiceProfiles\LocalService" -FileMask "advanced_ip_scanner_MAC.bin" -FolderName "Advanced_IP_Scanner_MAC___LocalService_User_Folder"

# 21. Advanced IP Scanner MAC - NetworkService User Folder
Collect-Artifact -SourceDir "C:\Windows\ServiceProfiles\NetworkService" -FileMask "advanced_ip_scanner_MAC.bin" -FolderName "Advanced_IP_Scanner_MAC___NetworkService_User_Folder"

# 22. Advanced IP Scanner Favorites - User Folder
$UserPath = Join-Path $env:USERPROFILE ""
Collect-Artifact -SourceDir "$UserPath" -FileMask "advanced_ip_scanner_Favorites.bin" -FolderName "Advanced_IP_Scanner_Favorites___User_Folder"

# 23. Advanced IP Scanner Favorites - User Temp Folder
$UserPath = Join-Path $env:USERPROFILE "AppData\Local\Temp\Advanced IP Scanner 2"
Collect-Artifact -SourceDir "$UserPath" -FileMask "advanced_ip_scanner_Favorites.bin" -FolderName "Advanced_IP_Scanner_Favorites___User_Temp_Folder"

# 24. Advanced IP Scanner Favorites - Windows Temp Folder
Collect-Artifact -SourceDir "C:\Windows\Temp\Advanced IP Scanner 2" -FileMask "advanced_ip_scanner_Favorites.bin" -FolderName "Advanced_IP_Scanner_Favorites___Windows_Temp_Folder"

# 25. Advanced IP Scanner Favorites - SYSTEM SysWOW64 User Folder
Collect-Artifact -SourceDir "C:\Windows\SysWOW64\config\systemprofile" -FileMask "advanced_ip_scanner_Favorites.bin" -FolderName "Advanced_IP_Scanner_Favorites___SYSTEM_SysWOW64_User_Folder"

# 26. Advanced IP Scanner Favorites - SYSTEM User Folder
Collect-Artifact -SourceDir "C:\Windows\System32\config\systemprofile" -FileMask "advanced_ip_scanner_Favorites.bin" -FolderName "Advanced_IP_Scanner_Favorites___SYSTEM_User_Folder"

# 27. Advanced IP Scanner Favorites - LocalService User Folder
Collect-Artifact -SourceDir "C:\Windows\ServiceProfiles\LocalService" -FileMask "advanced_ip_scanner_Favorites.bin" -FolderName "Advanced_IP_Scanner_Favorites___LocalService_User_Folder"

# 28. Advanced IP Scanner Favorites - NetworkService User Folder
Collect-Artifact -SourceDir "C:\Windows\ServiceProfiles\NetworkService" -FileMask "advanced_ip_scanner_Favorites.bin" -FolderName "Advanced_IP_Scanner_Favorites___NetworkService_User_Folder"

# 29. Advanced IP Scanner Favorites
Collect-Artifact -SourceDir "C:\" -FileMask "advanced_ip_scanner_Favorites.bin" -FolderName "Advanced_IP_Scanner_Favorites"

Write-Host "Collection complete!" -ForegroundColor Green

Save as .ps1 and run as Administrator. Use: powershell -ExecutionPolicy Bypass -File script.ps1

references

included in collections