Postmortem Autoruns...
 
Notifications
Clear all

Postmortem Autoruns Enumeration

4 Posts
3 Users
0 Reactions
373 Views
(@Anonymous)
Guest
Joined: 1 second ago
Posts: 0
Topic starter  

I know RegRipper can do a live system. I know that ProDiscover has the ability (with its ProScript functionality) to do postmortem with perl. Does anyone have a perl script already written I can use with ProDiscover OR perhaps another tool that enumerates the autorun registry entries on a "dead" drive?


   
Quote
(@kovar)
Prominent Member
Joined: 18 years ago
Posts: 805
 

Greetings,

RegRipper works just fine on "dead" systems….

-David


   
ReplyQuote
(@Anonymous)
Guest
Joined: 1 second ago
Posts: 0
Topic starter  

Thanks!


   
ReplyQuote
keydet89
(@keydet89)
Famed Member
Joined: 21 years ago
Posts: 3568
 

I know RegRipper can do a live system. I know that ProDiscover has the ability (with its ProScript functionality) to do postmortem with perl. Does anyone have a perl script already written I can use with ProDiscover OR perhaps another tool that enumerates the autorun registry entries on a "dead" drive?

Not sure what you mean by "RegRipper can do a live system". Tthrough F-Response, sure…but not when run from a CD or thumb drive.


   
ReplyQuote
Share: