Acquisition Tool Ad...
 
Notifications
Clear all

Acquisition Tool Advice

2 Posts
2 Users
0 Reactions
884 Views
(@egon_spengler)
Active Member
Joined: 2 years ago
Posts: 2
Topic starter  

Hello Everyone

I'm currently working on a script/tool using powershell to grab artefacts from the running system. I've managed to get everything working apart from locked files like the $MFT. Does anyone know if this can be done using powershell only?

Thanks in advance. 


   
Quote
mrpumba
(@mrpumba)
Estimable Member
Joined: 14 years ago
Posts: 116
 

Yes.  Look at Zimmermans tools, he has a parser for $MFT which utilizes Powershell and/or

CLI.


   
ReplyQuote
Share: