AdvancedIPScanner
Appsv1.1
Author: Reece394
description
Advanced IP Scanner Artifacts
paths
29 paths
› paths use Windows environment syntax
collection commands
# PowerShell Artifact Collection Script
# Target: AdvancedIPScanner
# Run as Administrator
#Requires -RunAsAdministrator
$ErrorActionPreference = "SilentlyContinue"
$DestBase = "D:\Evidence"
# Function to handle artifact collection with robocopy
function Collect-Artifact {
param (
[string]$SourceDir,
[string]$FolderName,
[string]$FileMask = "*"
)
$FullDest = Join-Path -Path $DestBase -ChildPath $FolderName
robocopy "$SourceDir" "$FullDest" "$FileMask" /E /COPY:DAT /R:0 /W:0 /NP /NFL /NDL /NJH /NJS | Out-Null
}
# 1. Advanced IP Scanner Aliases - User Folder
$UserPath = Join-Path $env:USERPROFILE ""
Collect-Artifact -SourceDir "$UserPath" -FileMask "advanced_ip_scanner_Aliases.bin" -FolderName "Advanced_IP_Scanner_Aliases___User_Folder"
# 2. Advanced IP Scanner Aliases - User Temp Folder
$UserPath = Join-Path $env:USERPROFILE "AppData\Local\Temp\Advanced IP Scanner 2"
Collect-Artifact -SourceDir "$UserPath" -FileMask "advanced_ip_scanner_Aliases.bin" -FolderName "Advanced_IP_Scanner_Aliases___User_Temp_Folder"
# 3. Advanced IP Scanner Aliases - Windows Temp Folder
Collect-Artifact -SourceDir "C:\Windows\Temp\Advanced IP Scanner 2" -FileMask "advanced_ip_scanner_Aliases.bin" -FolderName "Advanced_IP_Scanner_Aliases___Windows_Temp_Folder"
# 4. Advanced IP Scanner Aliases - SYSTEM SysWOW64 User Folder
Collect-Artifact -SourceDir "C:\Windows\SysWOW64\config\systemprofile" -FileMask "advanced_ip_scanner_Aliases.bin" -FolderName "Advanced_IP_Scanner_Aliases___SYSTEM_SysWOW64_User_Folder"
# 5. Advanced IP Scanner Aliases - SYSTEM User Folder
Collect-Artifact -SourceDir "C:\Windows\System32\config\systemprofile" -FileMask "advanced_ip_scanner_Aliases.bin" -FolderName "Advanced_IP_Scanner_Aliases___SYSTEM_User_Folder"
# 6. Advanced IP Scanner Aliases - LocalService User Folder
Collect-Artifact -SourceDir "C:\Windows\ServiceProfiles\LocalService" -FileMask "advanced_ip_scanner_Aliases.bin" -FolderName "Advanced_IP_Scanner_Aliases___LocalService_User_Folder"
# 7. Advanced IP Scanner Aliases - NetworkService User Folder
Collect-Artifact -SourceDir "C:\Windows\ServiceProfiles\NetworkService" -FileMask "advanced_ip_scanner_Aliases.bin" -FolderName "Advanced_IP_Scanner_Aliases___NetworkService_User_Folder"
# 8. Advanced IP Scanner Comments - User Folder
$UserPath = Join-Path $env:USERPROFILE ""
Collect-Artifact -SourceDir "$UserPath" -FileMask "advanced_ip_scanner_Comments.bin" -FolderName "Advanced_IP_Scanner_Comments___User_Folder"
# 9. Advanced IP Scanner Comments - User Temp Folder
$UserPath = Join-Path $env:USERPROFILE "AppData\Local\Temp\Advanced IP Scanner 2"
Collect-Artifact -SourceDir "$UserPath" -FileMask "advanced_ip_scanner_Comments.bin" -FolderName "Advanced_IP_Scanner_Comments___User_Temp_Folder"
# 10. Advanced IP Scanner Comments - Windows Temp Folder
Collect-Artifact -SourceDir "C:\Windows\Temp\Advanced IP Scanner 2" -FileMask "advanced_ip_scanner_Comments.bin" -FolderName "Advanced_IP_Scanner_Comments___Windows_Temp_Folder"
# 11. Advanced IP Scanner Comments - SYSTEM SysWOW64 User Folder
Collect-Artifact -SourceDir "C:\Windows\SysWOW64\config\systemprofile" -FileMask "advanced_ip_scanner_Comments.bin" -FolderName "Advanced_IP_Scanner_Comments___SYSTEM_SysWOW64_User_Folder"
# 12. Advanced IP Scanner Comments - SYSTEM User Folder
Collect-Artifact -SourceDir "C:\Windows\System32\config\systemprofile" -FileMask "advanced_ip_scanner_Comments.bin" -FolderName "Advanced_IP_Scanner_Comments___SYSTEM_User_Folder"
# 13. Advanced IP Scanner Comments - LocalService User Folder
Collect-Artifact -SourceDir "C:\Windows\ServiceProfiles\LocalService" -FileMask "advanced_ip_scanner_Comments.bin" -FolderName "Advanced_IP_Scanner_Comments___LocalService_User_Folder"
# 14. Advanced IP Scanner Comments - NetworkService User Folder
Collect-Artifact -SourceDir "C:\Windows\ServiceProfiles\NetworkService" -FileMask "advanced_ip_scanner_Comments.bin" -FolderName "Advanced_IP_Scanner_Comments___NetworkService_User_Folder"
# 15. Advanced IP Scanner MAC - User Folder
$UserPath = Join-Path $env:USERPROFILE ""
Collect-Artifact -SourceDir "$UserPath" -FileMask "advanced_ip_scanner_MAC.bin" -FolderName "Advanced_IP_Scanner_MAC___User_Folder"
# 16. Advanced IP Scanner MAC - User Temp Folder
$UserPath = Join-Path $env:USERPROFILE "AppData\Local\Temp\Advanced IP Scanner 2"
Collect-Artifact -SourceDir "$UserPath" -FileMask "advanced_ip_scanner_MAC.bin" -FolderName "Advanced_IP_Scanner_MAC___User_Temp_Folder"
# 17. Advanced IP Scanner MAC - Windows Temp Folder
Collect-Artifact -SourceDir "C:\Windows\Temp\Advanced IP Scanner 2" -FileMask "advanced_ip_scanner_MAC.bin" -FolderName "Advanced_IP_Scanner_MAC___Windows_Temp_Folder"
# 18. Advanced IP Scanner MAC - SYSTEM SysWOW64 User Folder
Collect-Artifact -SourceDir "C:\Windows\SysWOW64\config\systemprofile" -FileMask "advanced_ip_scanner_MAC.bin" -FolderName "Advanced_IP_Scanner_MAC___SYSTEM_SysWOW64_User_Folder"
# 19. Advanced IP Scanner MAC - SYSTEM User Folder
Collect-Artifact -SourceDir "C:\Windows\System32\config\systemprofile" -FileMask "advanced_ip_scanner_MAC.bin" -FolderName "Advanced_IP_Scanner_MAC___SYSTEM_User_Folder"
# 20. Advanced IP Scanner MAC - LocalService User Folder
Collect-Artifact -SourceDir "C:\Windows\ServiceProfiles\LocalService" -FileMask "advanced_ip_scanner_MAC.bin" -FolderName "Advanced_IP_Scanner_MAC___LocalService_User_Folder"
# 21. Advanced IP Scanner MAC - NetworkService User Folder
Collect-Artifact -SourceDir "C:\Windows\ServiceProfiles\NetworkService" -FileMask "advanced_ip_scanner_MAC.bin" -FolderName "Advanced_IP_Scanner_MAC___NetworkService_User_Folder"
# 22. Advanced IP Scanner Favorites - User Folder
$UserPath = Join-Path $env:USERPROFILE ""
Collect-Artifact -SourceDir "$UserPath" -FileMask "advanced_ip_scanner_Favorites.bin" -FolderName "Advanced_IP_Scanner_Favorites___User_Folder"
# 23. Advanced IP Scanner Favorites - User Temp Folder
$UserPath = Join-Path $env:USERPROFILE "AppData\Local\Temp\Advanced IP Scanner 2"
Collect-Artifact -SourceDir "$UserPath" -FileMask "advanced_ip_scanner_Favorites.bin" -FolderName "Advanced_IP_Scanner_Favorites___User_Temp_Folder"
# 24. Advanced IP Scanner Favorites - Windows Temp Folder
Collect-Artifact -SourceDir "C:\Windows\Temp\Advanced IP Scanner 2" -FileMask "advanced_ip_scanner_Favorites.bin" -FolderName "Advanced_IP_Scanner_Favorites___Windows_Temp_Folder"
# 25. Advanced IP Scanner Favorites - SYSTEM SysWOW64 User Folder
Collect-Artifact -SourceDir "C:\Windows\SysWOW64\config\systemprofile" -FileMask "advanced_ip_scanner_Favorites.bin" -FolderName "Advanced_IP_Scanner_Favorites___SYSTEM_SysWOW64_User_Folder"
# 26. Advanced IP Scanner Favorites - SYSTEM User Folder
Collect-Artifact -SourceDir "C:\Windows\System32\config\systemprofile" -FileMask "advanced_ip_scanner_Favorites.bin" -FolderName "Advanced_IP_Scanner_Favorites___SYSTEM_User_Folder"
# 27. Advanced IP Scanner Favorites - LocalService User Folder
Collect-Artifact -SourceDir "C:\Windows\ServiceProfiles\LocalService" -FileMask "advanced_ip_scanner_Favorites.bin" -FolderName "Advanced_IP_Scanner_Favorites___LocalService_User_Folder"
# 28. Advanced IP Scanner Favorites - NetworkService User Folder
Collect-Artifact -SourceDir "C:\Windows\ServiceProfiles\NetworkService" -FileMask "advanced_ip_scanner_Favorites.bin" -FolderName "Advanced_IP_Scanner_Favorites___NetworkService_User_Folder"
# 29. Advanced IP Scanner Favorites
Collect-Artifact -SourceDir "C:\" -FileMask "advanced_ip_scanner_Favorites.bin" -FolderName "Advanced_IP_Scanner_Favorites"
Write-Host "Collection complete!" -ForegroundColor Green› Save as .ps1 and run as Administrator. Use: powershell -ExecutionPolicy Bypass -File script.ps1