AdvancedPortScanner
Appsv1.1
Author: Reece394
description
Advanced Port Scanner Artifacts
paths
29 paths
› paths use Windows environment syntax
collection commands
# PowerShell Artifact Collection Script
# Target: AdvancedPortScanner
# Run as Administrator
#Requires -RunAsAdministrator
$ErrorActionPreference = "SilentlyContinue"
$DestBase = "D:\Evidence"
# Function to handle artifact collection with robocopy
function Collect-Artifact {
param (
[string]$SourceDir,
[string]$FolderName,
[string]$FileMask = "*"
)
$FullDest = Join-Path -Path $DestBase -ChildPath $FolderName
robocopy "$SourceDir" "$FullDest" "$FileMask" /E /COPY:DAT /R:0 /W:0 /NP /NFL /NDL /NJH /NJS | Out-Null
}
# 1. Advanced Port Scanner Aliases - User Folder
$UserPath = Join-Path $env:USERPROFILE ""
Collect-Artifact -SourceDir "$UserPath" -FileMask "advanced_port_scanner_Aliases.bin" -FolderName "Advanced_Port_Scanner_Aliases___User_Folder"
# 2. Advanced Port Scanner Aliases - User Temp Folder
$UserPath = Join-Path $env:USERPROFILE "AppData\Local\Temp\Advanced Port Scanner 2"
Collect-Artifact -SourceDir "$UserPath" -FileMask "advanced_port_scanner_Aliases.bin" -FolderName "Advanced_Port_Scanner_Aliases___User_Temp_Folder"
# 3. Advanced Port Scanner Aliases - Windows Temp Folder
Collect-Artifact -SourceDir "C:\Windows\Temp\Advanced Port Scanner 2" -FileMask "advanced_port_scanner_Aliases.bin" -FolderName "Advanced_Port_Scanner_Aliases___Windows_Temp_Folder"
# 4. Advanced Port Scanner Aliases - SYSTEM SysWOW64 User Folder
Collect-Artifact -SourceDir "C:\Windows\SysWOW64\config\systemprofile" -FileMask "advanced_port_scanner_Aliases.bin" -FolderName "Advanced_Port_Scanner_Aliases___SYSTEM_SysWOW64_User_Folder"
# 5. Advanced Port Scanner Aliases - SYSTEM User Folder
Collect-Artifact -SourceDir "C:\Windows\System32\config\systemprofile" -FileMask "advanced_port_scanner_Aliases.bin" -FolderName "Advanced_Port_Scanner_Aliases___SYSTEM_User_Folder"
# 6. Advanced Port Scanner Aliases - LocalService User Folder
Collect-Artifact -SourceDir "C:\Windows\ServiceProfiles\LocalService" -FileMask "advanced_port_scanner_Aliases.bin" -FolderName "Advanced_Port_Scanner_Aliases___LocalService_User_Folder"
# 7. Advanced Port Scanner Aliases - NetworkService User Folder
Collect-Artifact -SourceDir "C:\Windows\ServiceProfiles\NetworkService" -FileMask "advanced_port_scanner_Aliases.bin" -FolderName "Advanced_Port_Scanner_Aliases___NetworkService_User_Folder"
# 8. Advanced Port Scanner Comments - User Folder
$UserPath = Join-Path $env:USERPROFILE ""
Collect-Artifact -SourceDir "$UserPath" -FileMask "advanced_port_scanner_Comments.bin" -FolderName "Advanced_Port_Scanner_Comments___User_Folder"
# 9. Advanced Port Scanner Comments - User Temp Folder
$UserPath = Join-Path $env:USERPROFILE "AppData\Local\Temp\Advanced Port Scanner 2"
Collect-Artifact -SourceDir "$UserPath" -FileMask "advanced_port_scanner_Comments.bin" -FolderName "Advanced_Port_Scanner_Comments___User_Temp_Folder"
# 10. Advanced Port Scanner Comments - Windows Temp Folder
Collect-Artifact -SourceDir "C:\Windows\Temp\Advanced Port Scanner 2" -FileMask "advanced_port_scanner_Comments.bin" -FolderName "Advanced_Port_Scanner_Comments___Windows_Temp_Folder"
# 11. Advanced Port Scanner Comments - SYSTEM SysWOW64 User Folder
Collect-Artifact -SourceDir "C:\Windows\SysWOW64\config\systemprofile" -FileMask "advanced_port_scanner_Comments.bin" -FolderName "Advanced_Port_Scanner_Comments___SYSTEM_SysWOW64_User_Folder"
# 12. Advanced Port Scanner Comments - SYSTEM User Folder
Collect-Artifact -SourceDir "C:\Windows\System32\config\systemprofile" -FileMask "advanced_port_scanner_Comments.bin" -FolderName "Advanced_Port_Scanner_Comments___SYSTEM_User_Folder"
# 13. Advanced Port Scanner Comments - LocalService User Folder
Collect-Artifact -SourceDir "C:\Windows\ServiceProfiles\LocalService" -FileMask "advanced_port_scanner_Comments.bin" -FolderName "Advanced_Port_Scanner_Comments___LocalService_User_Folder"
# 14. Advanced Port Scanner Comments - NetworkService User Folder
Collect-Artifact -SourceDir "C:\Windows\ServiceProfiles\NetworkService" -FileMask "advanced_port_scanner_Comments.bin" -FolderName "Advanced_Port_Scanner_Comments___NetworkService_User_Folder"
# 15. Advanced Port Scanner MAC - User Folder
$UserPath = Join-Path $env:USERPROFILE ""
Collect-Artifact -SourceDir "$UserPath" -FileMask "advanced_port_scanner_MAC.bin" -FolderName "Advanced_Port_Scanner_MAC___User_Folder"
# 16. Advanced Port Scanner MAC - User Temp Folder
$UserPath = Join-Path $env:USERPROFILE "AppData\Local\Temp\Advanced Port Scanner 2"
Collect-Artifact -SourceDir "$UserPath" -FileMask "advanced_port_scanner_MAC.bin" -FolderName "Advanced_Port_Scanner_MAC___User_Temp_Folder"
# 17. Advanced Port Scanner MAC - Windows Temp Folder
Collect-Artifact -SourceDir "C:\Windows\Temp\Advanced Port Scanner 2" -FileMask "advanced_port_scanner_MAC.bin" -FolderName "Advanced_Port_Scanner_MAC___Windows_Temp_Folder"
# 18. Advanced Port Scanner MAC - SYSTEM SysWOW64 User Folder
Collect-Artifact -SourceDir "C:\Windows\SysWOW64\config\systemprofile" -FileMask "advanced_port_scanner_MAC.bin" -FolderName "Advanced_Port_Scanner_MAC___SYSTEM_SysWOW64_User_Folder"
# 19. Advanced Port Scanner MAC - SYSTEM User Folder
Collect-Artifact -SourceDir "C:\Windows\System32\config\systemprofile" -FileMask "advanced_port_scanner_MAC.bin" -FolderName "Advanced_Port_Scanner_MAC___SYSTEM_User_Folder"
# 20. Advanced Port Scanner MAC - LocalService User Folder
Collect-Artifact -SourceDir "C:\Windows\ServiceProfiles\LocalService" -FileMask "advanced_port_scanner_MAC.bin" -FolderName "Advanced_Port_Scanner_MAC___LocalService_User_Folder"
# 21. Advanced Port Scanner MAC - NetworkService User Folder
Collect-Artifact -SourceDir "C:\Windows\ServiceProfiles\NetworkService" -FileMask "advanced_port_scanner_MAC.bin" -FolderName "Advanced_Port_Scanner_MAC___NetworkService_User_Folder"
# 22. Advanced Port Scanner Favorites - User Folder
$UserPath = Join-Path $env:USERPROFILE ""
Collect-Artifact -SourceDir "$UserPath" -FileMask "advanced_port_scanner_Favorites.bin" -FolderName "Advanced_Port_Scanner_Favorites___User_Folder"
# 23. Advanced Port Scanner Favorites - User Temp Folder
$UserPath = Join-Path $env:USERPROFILE "AppData\Local\Temp\Advanced Port Scanner 2"
Collect-Artifact -SourceDir "$UserPath" -FileMask "advanced_port_scanner_Favorites.bin" -FolderName "Advanced_Port_Scanner_Favorites___User_Temp_Folder"
# 24. Advanced Port Scanner Favorites - Windows Temp Folder
Collect-Artifact -SourceDir "C:\Windows\Temp\Advanced Port Scanner 2" -FileMask "advanced_port_scanner_Favorites.bin" -FolderName "Advanced_Port_Scanner_Favorites___Windows_Temp_Folder"
# 25. Advanced Port Scanner Favorites - SYSTEM SysWOW64 User Folder
Collect-Artifact -SourceDir "C:\Windows\SysWOW64\config\systemprofile" -FileMask "advanced_port_scanner_Favorites.bin" -FolderName "Advanced_Port_Scanner_Favorites___SYSTEM_SysWOW64_User_Folder"
# 26. Advanced Port Scanner Favorites - SYSTEM User Folder
Collect-Artifact -SourceDir "C:\Windows\System32\config\systemprofile" -FileMask "advanced_port_scanner_Favorites.bin" -FolderName "Advanced_Port_Scanner_Favorites___SYSTEM_User_Folder"
# 27. Advanced Port Scanner Favorites - LocalService User Folder
Collect-Artifact -SourceDir "C:\Windows\ServiceProfiles\LocalService" -FileMask "advanced_port_scanner_Favorites.bin" -FolderName "Advanced_Port_Scanner_Favorites___LocalService_User_Folder"
# 28. Advanced Port Scanner Favorites - NetworkService User Folder
Collect-Artifact -SourceDir "C:\Windows\ServiceProfiles\NetworkService" -FileMask "advanced_port_scanner_Favorites.bin" -FolderName "Advanced_Port_Scanner_Favorites___NetworkService_User_Folder"
# 29. Advanced Port Scanner Favorites
Collect-Artifact -SourceDir "C:\" -FileMask "advanced_port_scanner_Favorites.bin" -FolderName "Advanced_Port_Scanner_Favorites"
Write-Host "Collection complete!" -ForegroundColor Green› Save as .ps1 and run as Administrator. Use: powershell -ExecutionPolicy Bypass -File script.ps1