594 B
594 B
Kroll Artifact Parser
- Collect and processes artifacts on windows
- Collects from live systems, mounted images and F-response tool
Targets
- Needs source and target directory, as well as a module to process the files on
Targetcopies a file into a repository*.tkapefiles contains metadata of the files to copyCompound Targetscontain metadata of multiple files in order to get a result quicker!Disabledo not appear in the target list!Localkeep on local
Modules
- Used on the targeted files
*.mkapefiles- Additional binaries are kept in
bin