dfirhub

RemoteAdmin

CompoundCompoundv2.1

Author: Drew Ervin, Mathias Frank, Andrew Rathbun, Phill Moore

description

Composite target for files related to remote administration tools

includes (26)

paths

107 pathsfrom 26 targets
paths use Windows environment syntax

collection commands

# PowerShell Collection Script
# Target: RemoteAdmin (Compound Target)
# Use KAPE for compound target collection:
# kape.exe --tsource C: --tdest D:\Evidence --target RemoteAdmin

Write-Host "For compound targets, use KAPE directly for best results." -ForegroundColor Yellow

Save as .ps1 and run as Administrator. Use: powershell -ExecutionPolicy Bypass -File script.ps1

Note: This is a compound target that references 29 other targets. KAPE will automatically collect all referenced artifacts.

references