Skip to content

Releases: CyberDefenseInstitute/CDIR-A

2512

11 Dec 06:39

Choose a tag to compare

prefetch.exe has been updated.

  • prefetch.exe now supports prefetch format version 31.
  • An error that occurred when parsing prefetch files stored on file systems other than NTFS using prefetch.exe has been fixed.

2306

23 Jun 02:06

Choose a tag to compare

add HKCU\Environment\UserInitMprLogonScript to regruns check target

2207

05 Jul 23:25

Choose a tag to compare

fix usnjrnl encoding issue

2010

08 Oct 02:59

Choose a tag to compare

  • prefetch.py
    • fixed interpretation of run count information
  • amcache.py
    • fixed bug so as to correctly write the header when ingesting multiple target hosts
    • added "--no-header-inventory" option
  • upgrade third party tools
    • BrowsingHistoryView.exe: 2.25 to 2.41
    • NetworkUsageView.exe: 1.13 to 1.20

2001

01 Jan 06:22

Choose a tag to compare

  • prefetch.py, amcache.py, usnjrnl.py, parserutility.py, PyWMIPersistenceFinder.py

    • modified to run on python3.
      errors may occur on python2.
  • prefetch.exe, amcache.exe, usnjrnl.exe, parserutility.exe, PyWMIPersistenceFinder.exe

    • replaced with the ones from the modified *.py above.

1910

10 Oct 03:56

Choose a tag to compare

  • prefetch.exe

    • add functionality to parse the prefetch file in ADS.
    • fix bug so as to correctly parse the run count contained in prefetch files of Windows 10 version 1903.
  • upgrade third party tools

    • Secure2Csv64.exev: 1.0.0.8 to 1.0.0.9
    • NetworkUsageView.exe: 1.12 to 1.13
    • BrowsingHistoryView.exe: 2.17 to 2.25

1902

12 Feb 05:08

Choose a tag to compare

  • mft.exe
    • improved handling of path name
    • fixed interpretation of size information
    • fixed processing of -e option
  • regruns.exe and shimcache.exe
    • fixed even if a hive is dirty and no transaction logs
    • workaround for handling of irregular key
  • LPSLibrary_CDI.XML
    • added a query for network status
    • splitted into two queries about sleep and clocks change
  • prefetch.exe
    • fixed processing if a prefetch file is truncated
  • added third party tools:
    • BrowsingHistoryView.exe
    • NetworkUsageView.exe
    • PyWMIPersistenceFinder.exe
    • Secure2Csv64.exe

1806

07 Jun 08:08

Choose a tag to compare

  • CDIR-C 1.3 compatible (naming rules of filename and diretory)
  • mft.exe: added securityID column
  • amcache.exe: fixed when specific key not found
  • regruns: support parsing of transaction log

1802

15 Feb 02:08

Choose a tag to compare

  • amcache.exe: updated for Windows 10 (1709) format partially
  • shimcache.exe: updated for Windows 10 (1703) format
  • mft.exe: fixed some file record shows wrong value of file size

1706

03 Jul 05:48

Choose a tag to compare

update 1706