Notifications
Clear all

ProScripts posted

1 Posts
1 Users
0 Reactions
734 Views
keydet89
(@keydet89)
Famed Member
Joined: 21 years ago
Posts: 3568
Topic starter  

For those using ProDiscover, I've posted a couple of ProScripts to the updated TechPathways forums…

I reposted the UserDump.pl script which pulls user info and group membership from the SAM portion of the Registry, parsing the F, V, and C values. I've added a ProScript that lets you copy out the EventLog files, so you can parse them with FileReadEvt, and I've added a ProScript that parses the UserAssist keys from the HKEY_USERS hive, translating the ROT-13 "encryption" and parsing the datetime stamps.

Harlan


   
Quote
Share: