Releases: SekoiaLab/Fastir_Collector
Releases · SekoiaLab/Fastir_Collector
V1.1 Release
N.B. : Binaries have been moved from the git repository to this page.
Additions
- When available, scheduled jobs will now use
at - fs module will now report
startupdirectories content - New cli option :
--output_typeto choose between a csv or json output
Bugfixes
- Fixed unpack size in timestamps for Windows < 7
- Eased compilation (Bugfixes + doc)
- Health module was off for several modules, fixed
- Several JSON modes bugs fixed, now also generate sha256 of log files
- Generated JSON files are now standard-compliant
_firefox_history.csv,_Filecatcher.csvand_evts.csvnow have headers- In
hash_processes, type is now"hash processes" - In
network_list, type is nownetwork_list - Network timestamps are properly formatted
- All Windows versions should output scheduled jobs now
- Fixed HOMEDRIVE not being set
- Fixed the detection of NTUSER.DAT files
- Registry module should work more consistently across Windows versions
- UserAssist count is no longer 1 time ahead for Win7 and above
- Filecatcher will now scan a directory only once
Values changed
- Registries module now uses hexadecimal notation for values it can not decode rather than skipping them
- Filecatcher will now use real path rather than VSS path
Output paths changes
_tasks.*is removed, as it was a poorly formatted equivalent of_scheduled_jobs.*.
N.B. Those changes fix mostly differences between JSON and CSV outputs for the same information.
_list_running.jsonis now_processes.json_list_shares.jsonis now_shares.json_networks_drives.jsonis now_list_networks_drives.json_list_services.jsonis now_services.json_shellbag.jsonis now_shellbags.json_run_mru_start.jsonis now_run_MRU_start.json_custom_registry.jsonis now_custom_registry_keys.json_processes_dlls.jsonis now correctly generated_hash_processes.jsonis now correctly generated
RMLL Releases
We have add new features and decide to make a release:
- Dump raw registry, SAM
- Networks lists registry
- Export MFT raw only
- Collects system information with SeDebugPrivilege
- Collect files recorded in autorun registry
- Collect specify keys
- Export json for all artefacts