SlopScore
20 crowdincl. 3 critics

win11-triage-collector

Windows 11 forensic artifact collection tool for live systems and mounted forensic images
Open repo on GitHubgithub.com/Jumbalicious79/win11-triage-collector
PowerShell · ★ 1 · 0 forks · MIT · paperwork by the Cap'mmostly ai (inferred)light human (inferred)works-on-my-machine (inferred)other
listed 1 hour ago by Jumbalicious79 · last checked 1 hour ago
The owner didn't write this. This repo never submitted itself. The Cap'm found it on a truffle trawl and wrote its paperwork from what GitHub already shows. Picked by hand by the Cap'm on 2026-10-07: Windows 11 forensic artifact collection tool for live systems and mounted forensic images; its own README says "All PowerShell (Anthropic) scripts, batch launchers, and supporting code were written by Claude Code (claude". 1 stars; MIT license. The owner did not submit this. Votes count; awards don't until the owner claims it.

I'm not calling your project slop! Geeze, it's a joke... Do you own this repo?

Log in with GitHub as Jumbalicious79. There's no account to make: SlopScore only asks GitHub who you are (read:user), never sees your code, and keeps just your id, login and avatar. Then you can:

  • Keep it, on your terms. Commit your own slopscore.md (spec) and press Refresh. Your paperwork replaces the Cap'm's, and you can submit it for Slop of the Day.
  • Take it down. One click on Remove. It stays gone; the trawl never brings it back.

Log in with GitHub

Can't log in as the owner? Request a takedown. No login needed, and a trawled listing comes down right away.

GitHub says
Windows 11 forensic artifact collection tool for live systems and mounted forensic images
created
2026-04-10 · pushed 5 hours ago · 23 commits · 1 contributor
languages
PowerShell 99%Batchfile 1%
paperwork
licensereadme 42% health
dependencies
no dependency graph (no manifest, or disabled) · OSV.dev, checked 1 hour ago

Disclosures, inferred by the Cap'm

slopbucket
vibe-coded
category
other
ai_generated
mostly
human_touch
light
status
works-on-my-machine
language (detected)
batchfilepowershell
license (detected)
mit

The Cap'm's log

The Cap'm wrote this paperwork, not the owner. This repo never submitted itself to SlopScore. The Cap'm picked it by hand: Windows 11 forensic artifact collection tool for live systems and mounted forensic images; its own README says "All PowerShell (Anthropic) scripts, batch launchers, and supporting code were written by Claude Code (claude". It carries the MIT license. The disclosures above are his best guess from what GitHub shows.

Is this yours? Commit a real slopscore.md and press Refresh to replace this, or remove the listing in one click. There's no account to make: you log in with GitHub.

README — the repo's own words, folded up so the grading fits on one screen
# Windows 11 Forensic Triage Collector

A lightweight, dependency-free PowerShell script for collecting forensic
artifacts from a live Windows system. Pure PowerShell -- no KAPE, no external
tools required.

Designed to be used with win11-timeline-builder, which parses this script's
output into a unified chronological timeline and auto-opens it in Timeline
Explorer. Both tools are available as separate repos for independent use.

  Companion project: https://github.com/Jumbalicious79/win11-timeline-builder

Tested on Windows 11 Home Build 26200 (x64) and Windows 11 Pro 26100 (ARM64,
Parallels on Apple silicon). A typical run collects ~450-500 files in about
1-2 minutes; the zip size depends mostly on the raw $MFT (often 100 MB to
several GB). Supports live system collection and mounted forensic images.


## Setup

Both tools MUST be sibling directories (same parent folder) for the automatic
workflow to function. The timeline builder locates triage collections by looking
for ..\win11-triage-collector\reports\ relative to its own location.

Required directory structure:

  any-parent-folder\
    win11-triage-collector\       <-- this repo
      triage-collector.ps1
      Run-TriageCollector.bat
      README.txt
      tools\                      <-- optional tools (each in own subfolder)
        dumpit\                   <-- optional: DumpIt for memory capture
                                      (download yourself; see its README.txt)
      reports\                    <-- collections save here
    win11-timeline-builder\       <-- companion repo
      timeline-builder.ps1
      Run-TimelineBuilder.bat
      README.txt
      tools\                      <-- auto-downloaded tools (each in own subfolder)
        sqlite3\                  <-- auto-downloaded: browser history parser
        TimelineExplorer\         <-- auto-downloaded: forensic CSV viewer
        volatility3\              <-- optional: vol.exe for memory analysis
      reports\                    <-- timelines save here

To set up:

  git clone https://github.com/Jumbalicious79/win11-triage-collector
  git clone https://github.com/Jumbalicious79/win11-timeline-builder

Or download both repos and extract them into the same parent folder. The parent
folder can be anywhere -- your desktop, a USB drive, a network share, etc.

If you only need the collector without timeline analysis, it works standalone.
But for the full collect-and-analyze workflow, both directories must be siblings.


## Intended Workflow

These two tools are designed to work together as a complete collect-and-analyze
pipeline:

  1. COLLECT: Run triage-collector on the target system (this tool)
  2. ANALYZE: Run timeline-builder on the collection (companion tool)
  3. REVIEW: Timeline Explorer auto-opens with the timeline loaded

### Live System (Dirty Forensics)

For incident response, triage, or non-legal investigations where speed matters
more than forensic purity:

  1. Copy win11-triage-collector to a USB drive
  2. Plug the USB into the target machine
  3. Double-click Run-TriageCollector.bat (collects to reports\ on the USB)
  4. Unplug the USB and take it to your analysis workstation
  5. Place win11-timeline-builder alongside the collector (or anywhere)
  6. Double-click Run-TimelineBuilder.bat -- it auto-finds the triage zips
  7. Pick a collection, timeline builds, Timeline Explorer opens

This is a "dirty" collection -- the act of running the script modifies the
system (writes files, creates a shadow copy, touches the registry). This is
acceptable for triage and incident response but may not meet evidentiary
standards for legal proceedings.

### Forensic Image (Clean Forensics)

For legal cases, litigation hold, or any situation requiring chain of custody:

  1. Create a forensic image of the target system FIRST
     Use FTK Imager, dd, or your preferred imaging tool
  2. Mount the image as read-only on your analysis workstation (e.g., E:)
  3. Run triage-collector against the mounted drive letter:
     Run-TriageCollector.bat E
     (or: powershell ... -File triage-collector.ps1 -TargetDrive E)
  4. Run timeline-builder against the collection
  5. The collection manifest (SHA256 hashes) provides integrity verification

When collecting from a mounted image, the script auto-detects that the target
is not the live system drive and switches to MOUNTED IMAGE mode:

  Collected (file-copy):
    - Raw $MFT, $LogFile and $UsnJrnl:$J, read from the volume itself, when
      the image is mounted as an NTFS volume whose root is the drive letter
      (skipped for nested layouts such as E:\C\Windows)
    - Registry hives (from Windows\System32\config\)
    - Event logs (from Windows\System32\winevt\Logs\)
    - Prefetch files, browser data, user activity artifacts
    - Scheduled task XML definitions (from Windows\System32\Tasks\)
    - Startup folder listings (all-users folder + every user profile)
    - AV log files (Defender support logs, third-party AV logs)
    - USB setupapi.dev.log and rotated setupapi.dev.<date>.log files
    - Amcache.hve (+ .LOG1/.LOG2 transaction logs)

  Skipped (requires live system):
    - Network state (DNS, ARP, TCP connections, firewall, Wi-Fi)
    - Live registry queries (Run keys, BAM, RecentApps, USB registry,
      mounted devices) -- the same data is in the collected hives
    - USB PnP device timestamps (usb_storage_devices.csv)
    - Scheduled task run times (scheduled_tasks.csv)
    - WMI queries (services, startup commands, drivers, WMI subscriptions)
    - Defender cmdlets (detections, status, preferences)
    - Shadow copies (not needed -- files are not locked)
    - systeminfo (would report collector host, not target)

### USB Deployment Kit

To prepare a USB drive as a portable forensic triage kit:

  USB_DRIVE\
    win11-triage-collector\
      triage-collector.ps1
      Run-TriageCollector.bat
      README.txt
      tools\                      <-- optional: memory capture tool
        dumpit\                   <-- DumpIt download extracted here
      reports\                    <-- collections save here
    win11-timeline-builder\
      timeline-builder.ps1
      Run-TimelineBuilder.bat
      README.txt
      tools\                      <-- sqlite3\, TimelineExplorer\, volatility3\
      reports\                    <-- timelines save here

Both tools output to their own reports\ directories. The timeline builder
auto-discovers triage collections from the sibling directory. No configuration
needed -- plug in, double-click, collect, analyze.


## Quick Start

### Double-click (recommended)

  Run-TriageCollector.bat              -- collect from C: (live system)
  Run-TriageCollector.bat fast         -- skip the raw NTFS copies and the
                                          USN journal export
  Run-TriageCollector.bat nozip        -- don't compress output
  Run-TriageCollector.bat E            -- collect from E: (mounted image)
  Run-TriageCollector.bat E fast       -- collect from E:, skip the raw NTFS
                                          copies and the USN journal export

  Note: "fast" skips the raw NTFS copies ($MFT, $LogFile, $UsnJrnl:$J) and
  the fsutil USN journal export -- the timeline builder's largest sources of
  file activity, and the largest files in the collection. Registry hives are
  always collected.

  For memory capture: extract Magnet DumpIt into tools\dumpit\ (see
  tools\dumpit\README.txt). The script prompts on live system runs when a
  capture tool is detected. See the "Optional Tools" section below.

### PowerShell (Admin)

  powershell -ExecutionPolicy Bypass -NoProfile -File "path\to\triage-collector.ps1"
  powershell -ExecutionPolicy Bypass -NoProfile -File "path\to\triage-collector.ps1" -TargetDrive E
  powershell -ExecutionPolicy Bypass -NoProfile -File "path\to\triage-collector.ps1" -SkipLargeFiles
  powershell -ExecutionPolicy Bypass -NoProfile -File "path\to\triage-collector.ps1" -Categories "Network","Persistence","EventLogs"
  powershell -ExecutionPolicy Bypass -NoProfile -File "path\to\triage-collector.ps1" -NoCompress


## How It Handles Windows Defender

Collecting registry hives (SAM, SECURITY) from a live system triggers Defender's
Trojan:Win32/SAMDumpz detection because that's exactly what credential dumping
tools do. This script handles it automatically:

  1. Adds a temporary Defender exclusion for the output folder at script start
  2. Collects all 4 hives (SYSTEM, SOFTWARE, SAM, SECURITY) via "reg save"
  3. Removes the exclusion at script end -- also when the run is stopped
     with Ctrl+C or ends with an error

This is the same approach KAPE uses. The script runs as Administrator, so it has
the privileges to manage Defender exclusions. You do NOT need to manually disable
Defender or add exclusions.

If the exclusion fails (e.g., tamper protection blocks it), the script warns you
and continues -- SYSTEM and SOFTWARE will still collect fine, but SAM/SECURITY
may be blocked by Defender.


## Output

The script compresses everything into a single .zip and removes the uncompressed
folder automatically. Only the .zip remains:

  win11-triage-collector\
    reports\
      TriageCollection_2026-04-08_08-04.zip    (~60 MB)

If memory capture was included, the memory dump is saved next to the zip,
not inside it (it is as large as the machine's RAM):

  win11-triage-collector\
    reports\
      TriageCollection_2026-04-08_08-04.zip                (artifacts)
      TriageCollection_2026-04-08_08-04_memory_dump.dmp    (= RAM size; DumpIt)

DumpIt writes a Microsoft crash dump (.dmp); WinPmem and Magnet RAM Capture
write a raw image (memory_dump.raw).

Use -NoCompress to keep the uncompressed folder instead.

Inside the zip:

  TriageCollection_2026-04-08_08-04\
    collection_info.json              -- host, mode, start time, time zones
    collection_log.txt                -- full run log
    collection_manifest.csv           -- SHA256, source, dest, size, source file
                                         times per file (see Output File Formats)
    systeminfo.txt                    -- system info snapshot
    Memory\                               -- only if memory capture was selected
      memory_dump.dmp / .raw          -- full RAM dump (saved separately, not in zip)
      memory_acquisition_log.txt      -- capture tool output log
    FileSystem\
      $MFT                            -- Master File Table, raw copy
      $LogFile                        -- NTFS transaction log, raw copy
      $UsnJrnl_$J                     -- USN Journal, raw copy of the
                                         allocated part (binary records)
      $UsnJrnl_$J.txt                 -- USN Journal (fsutil CSV-style text)
    Registry\
      SYSTEM                          -- hardware, services, USB history, timezone
      SOFTWARE                        -- installed apps, network profiles, Run keys
      SAM                             -- local user accounts, password policy
      SECURITY                        -- security policies, audit settings
      Amcache.hve                     -- program execution history with SHA1 hashes
      Amcache.hve.LOG1/.LOG2          -- transaction logs for dirty hive recovery
      buzz_\                          -- per-user: NTUSER.DAT, UsrClass.dat
    EventLogs\
      System.evtx                     -- service events, shutdowns, driver loads
      Security.evtx                   -- logons, process creation, account changes
      Application.evtx                -- app crashes, errors
      Microsoft-Windows-PowerShell%4Operational.evtx
      Microsoft-Windows-TerminalServices-LocalSessionManager%4Operational.evtx
      Microsoft-Windows-Windows Defender%4Operational.evtx
      Microsoft-Windows-Bits-Client%4Operational.evtx
      (Sysmon, Task Scheduler -- if present on the system)
    Execution\
      Prefetch\                       -- all .pf files (program execution evidence)
      RecentApps\<user>\RecentApps.reg  -- per logged-in user, only if the key
                                         exists (absent on Windows 11)
      bam_entries.csv                 -- BAM: per-user program paths with
                                         decoded last-execution times (UTC)
      appcompat_cache.reg             -- ShimCache execution artifacts
    Network\
      dns_cache.txt                   -- recently resolved domains
      arp_cache.txt                   -- local network neighbors
      netstat.txt                     -- active connections snapshot
      tcp_connections.csv             -- connections with process info
      network_profiles.txt            -- Wi-Fi/wired network history
      firewall_rules.txt              -- all firewall rules
      wifi_profiles.txt               -- saved Wi-Fi profiles
      network_shares.txt              -- SMB shares
    UserActivity\
      buzz_\
        RecentFiles\                  -- LNK shortcut files (file access history)
        JumpLists\                    -- AutomaticDestinations, CustomDestinations
        ConsoleHost_history.txt       -- PowerShell command history
    Browser\
      buzz_\
        Chrome\                       -- History, Bookmarks, Login Data, etc.
          <profile>\Network\Cookies   -- cookies (current Chromium location)
        Edge\                         -- same artifacts as Chrome
      (Firefox -- if installed)
    USB\
      setupapi.dev.log                -- device installation log (first-connect times)
      setupapi.dev.<yyyymmdd_hhmmss>.log  -- older logs rotated by Windows
                                         (all present are collected)
      usb_storage_devices.csv         -- USB storage devices (incl. disconnected)
                                         with first install / arrival / removal
                                         times (UTC)
      usb_storage_devices.txt         -- USB storage device registry entries
      usb_devices.txt                 -- all USB device entries
      mounted_devices.txt             -- volume GUID to drive letter mapping
    Persistence\
      scheduled_tasks.csv             -- all scheduled tasks (incl. disabled) with
                                         run-as account, actions, triggers,
                                         registration/last/next run times
      services.csv                    -- all services with binary paths and
                                         registry key last-write time
      startup_entries.csv             -- startup programs
      run_keys.csv                    -- Run/RunOnce values for HKLM and every
                                         logged-in user, with key last-write time
      run_keys.txt                    -- same keys (plus Shell Folders) as text
      startup_folders.csv             -- Startup folder items for all users and
                                         every profile, with file times (UTC)
      startup_folders.txt             -- same folders as text
      wmi_subscriptions.csv           -- WMI event consumers (persistence)
      drivers.csv                     -- kernel drivers with registry key
                                         last-write time
      loaded_dlls_suspicious.txt      -- DLLs loaded from non-standard paths
    AntiVirus\
      installed_av_products.txt       -- all AV products detected via WMI
      defender_detections.csv         -- Defender threat detection history
      defender_threats.csv            -- Defender threat catalog
      defender_status.txt             -- Defender real-time status
      defender_preferences.txt        -- Defender configuration/exclusions
      Defender\                       -- Defender support logs (last 10)
      Symantec_SEP\                   -- if installed
      CrowdStrike\                    -- if installed
      SentinelOne\                    -- if installed
      CarbonBlack\                    -- if installed
      Malwarebytes\                   -- if installed
      Sophos\                         -- if installed
      ESET\                           -- if installed
      Kaspersky\                      -- if installed
      McAfee_Trellix\                 -- if installed
      Bitdefender\                    -- if installed
      TrendMicro\                     -- if installed
      Webroot\                        -- if installed
      Norton\                         -- if installed
      Cylance\                        -- if installed


## What Gets Collected

### Memory (opt-in, live system only)

  memory_dump.dmp    Full physical RAM capture: a Microsoft crash dump from
                     DumpIt (preferred), or memory_dump.raw from WinPmem or
                     Magnet RAM Capture -- whichever is found in tools\.
                     Dump size equals installed RAM. Runs first to capture
                     pristine memory state before other collection.
                     Requires a capture tool in tools\ -- see Optional Tools.
                     Saved separately from the zip due to size.

### FileSystem

  NTFS metafiles cannot be opened through the normal file APIs (not even in a
  Volume Shadow Copy). The script reads them straight from the volume with a
  built-in raw NTFS reader (C# compiled at run time via Add-Type, no
  third-party tools): it finds $MFT from the boot sector, then each metafile's
  file record and the clusters of its data, including data split across
  several MFT records ($ATTRIBUTE_LIST). The copies are the on-disk bytes, for
  the timeline builder's $MFT timeline and for external tools such as
  MFTECmd (see Analyzing the Output).

  $MFT          FileSystem\$MFT -- Master File Table: one record per file and
                folder, including deleted ones whose records are not yet
                reused (names, parent folders, $STANDARD_INFORMATION and
                $FILE_NAME times, sizes). Typically 100 MB to a few GB.
  $LogFile      FileSystem\$LogFile -- NTFS transaction log (recent metadata
                changes). Usually 64 MB.
  $UsnJrnl:$J   FileSystem\$UsnJrnl_$J -- USN change journal: every create,
                modify, delete, rename. $J is a sparse stream: Windows frees
                the oldest part as the journal grows, so its logical size can
                be many GB while only the newest part (typically tens of MB)
                is stored. The copy holds only that allocated part, in order;
                the freed (all-zero) part is left out. MFTECmd and similar
                tools parse this layout directly.
                The same journal is also exported as text with "fsutil usn
                readjournal ... csv" into FileSystem\$UsnJrnl_$J.txt, which
                the timeline builder parses.

  Raw copies need Administrator rights and an NTFS volume: the live system
  drive, or a mounted image whose Windows folder is at the root of its drive
  letter. Anything else (no access, damaged metadata, nested image layout)
  is logged and the collection goes on; the fsutil export runs regardless.
  -SkipLargeFiles ("fast") skips the raw copies and the fsutil export.

### Registry Hives

  SYSTEM        Hardware, services, mounted devices, USB, timezone.
  SOFTWARE      Installed apps, OS version, network profiles, Run keys.
  SAM           Local accounts, group memberships, last login times.
  SECURITY      Security policies, audit settings, LSA secrets.
  NTUSER.DAT    Per-user: recent docs, typed URLs, UserAssist, MRU lists.
                Locked for active user -- requires VSS.
  UsrClass.dat  ShellBags (folder browsing history). Locked for active user.
  Amcache.hve   Program execution history with SHA1 hashes and install dates.
                Transaction logs (.LOG1/.LOG2) collected for dirty hive recovery.

### Event Logs

  System.evtx                Service starts/stops, shutdowns, driver loads.
  Security.evtx              Logons (4624/4625), process creation, audit changes.
  Application.evtx           App crashes, errors, warnings.
  PowerShell Operational     Script block and module logging.
  Sysmon (if installed)      Process, network, file, registry activity.
  Task Scheduler             Task creation/modification/execution.
  TerminalServices           RDP logins (lateral movement).
  Windows Defender           Detections, scans, exclusion changes.
  BITS Client                Background transfers (stealthy downloads).

### Execution Artifacts

  Prefetch (.pf)             Last 8 execution times per program.
  BAM                        Background Activity Moderator: last execution
                             time per program per user (all user SIDs, decoded
                             to UTC in bam_entries.csv). Live system only.
  AppCompatCache             ShimCache -- program presence/execution evidence.
  RecentApps                 Recently launched apps with run counts, for every
                             logged-in user. The key does not exist on Windows
                             11 and recent Windows 10 builds; nothing is written
                             then.

### Network

  DNS cache                  Recently resolved domains (C2 indicators).
  ARP cache                  Local network neighbors.
  netstat / TCP connections  Active connections with process info.
  Network profiles           Wi-Fi/wired network history.
  Firewall rules             Allowed/blocked traffic rules.
  Wi-Fi profiles             Saved wireless networks.
  Network shares             Active SMB shares.

### User Activity

  LNK files                  File access with timestamps and original paths.
  Jump Lists                 Recent/frequent files per application.
  PowerShell history         PSReadLine command history (plaintext).

### Browser

  History, Bookmarks, Login Data, Cookies, Downloads, Preferences.
  Supports Chrome, Edge, Brave, Opera, Opera GX, Vivaldi (all Chromium-based)
  and Firefox. Per-user, per-profile.
  Cookies of the Chromium-based browsers: current versions keep them in
  <profile>\Network\Cookies (collected to <profile>\Network\Cookies, with
  Network\Cookies-journal if present); the profile-root Cookies file of
  older versions is collected too when it exists.

### USB

  setupapi.dev*.log          Device install timestamps (first USB connect).
                             Windows rotates setupapi.dev.log into
                             setupapi.dev.<yyyymmdd_hhmmss>.log files; all of
                             them are collected with their original names.
  USB storage PnP times      usb_storage_devices.csv: every USB storage disk
                             known to Plug and Play, including devices that are
                             not connected, with first install, install, last
                             arrival and last removal times. Live system only.
  USB storage/device registry  Serial numbers, vendor IDs, mount points.
  Mounted devices            Volume GUID to drive letter mapping.

### Persistence

  Scheduled tasks            All tasks, including disabled ones, with run-as
                             account, actions, triggers, registration date and
                             last/next run time and last result.
  Services                   Service binary paths, startup types, accounts, and
                             last-write time of each service's registry key.
  Startup entries            Registry and folder-based autostart.
  Run/RunOnce keys           Registry autostart keys for HKLM and for every
                             logged-in user (not just the account running the
                             collector), with key last-write times.
  Startup folders            All-users Startup folder and every user profile's
                             Startup folder (live system and mounted images),
                             with created/modified times. Hidden items are
                             listed; desktop.ini is skipped.
  WMI subscriptions          Event-driven persistence.
  Drivers                    Kernel and filesystem drivers, with last-write
                             time of each driver's registry key.
  Loaded DLLs               DLLs from non-standard paths (sideloading).

### AntiVirus / Endpoint Security

  Installed AV products      All registered AV products via WMI SecurityCenter2.
  Windows Defender           Detection history, threat catalog, real-time status,
                             configured preferences/exclusions, and support logs.
  Third-party AV logs        Auto-detected and collected if installed:
                             Symantec SEP, CrowdStrike Falcon, SentinelOne,
                             Carbon Black, Malwarebytes, Sophos, ESET,
                             Kaspersky, McAfee/Trellix, Bitdefender, Trend Micro,
                             Webroot, Norton, Cylance.
  AV event logs              Windows event logs from AV products (Symantec,
                             CrowdStrike) collected via wevtutil if present.


## Output File Formats

All times in the JSON and CSV files below are UTC in ISO 8601 round-trip
format, e.g. 2026-10-07T01:52:50.0000000Z. A blank field means the time is
unknown or does not apply. CSV files are UTF-8 with a header row and standard
quoting (Import-Csv, Excel and Timeline Explorer read them directly). A CSV
with only a header row means the query ran and found nothing.

### collection_info.json

Written at the start of the run, at the root of the collection:

  SchemaVersion        1
  ComputerName         Machine running the collector
  CollectorUser        Account that ran the collector
  Mode                 "Live" or "MountedImage"
  TargetDrive          Drive letter collected from, e.g. "C"
  TargetRoot           Windows root on that drive, e.g. "C:\"
  CollectionStartUtc   Start of the run
  CollectorTimeZoneId  Time zone of the collecting machine
  CollectorCulture     Culture (locale) of the collecting machine, e.g. "en-US"
  TargetTimeZoneId     Time zone of the examined Windows install. Live: same
                       as CollectorTimeZoneId. Mounted image: TimeZoneKeyName
                       from the image's SYSTEM hive, or null if unreadable.

The timeline builder uses these to convert local-time text (USN journal,
setupapi logs) correctly even when the analysis machine uses a different
time zone or locale.

### collection_manifest.csv

  SHA256               Hash of the collected copy
  SourcePath           Original path; "HKLM\..." / "HKU\..." for reg save,
                       "(shadow)..." for shadow copies, "(command: ...)" for
                       command output, "(raw NTFS \\.\C: $MFT)" etc. for the
                       raw NTFS copies
  DestPath             Full path of the copy at collection time
  SizeBytes            Size of the copy
  CollectedAt          Collector's local time when the file was recorded
  RelativePath         Path inside the collection, e.g.
                       Execution\Prefetch\CMD.EXE-0BD30981.pf
  SourceCreatedUtc     Created / modified / accessed times of the ORIGINAL
  SourceModifiedUtc    file (the copies in the collection get new times).
  SourceAccessedUtc    Blank for command output, reg save exports, or unknown.

The first five columns are unchanged from earlier versions; the last four are
appended.

### Execution\bam_entries.csv  (live system only)

  Sid                  SID of the user the BAM entry belongs to
  User                 Account name (profile folder name), blank if unknown
  Path                 Program path as recorded by BAM
                       (\Device\HarddiskVolumeN\...) or app ID
  LastExecutionUtc     Last execution time

Replaces bam_entries.txt from earlier versions, which lost the times (only the
first 4 of the 8 FILETIME bytes were written).

### Persistence\scheduled_tasks.csv  (live system only)

  TaskName, TaskPath, State, Author
  UserId               Account the task runs as (group name for group tasks)
  Actions              Command lines; COM handler actions as
                       "ComHandler {CLSID} <data>"
  Triggers             Trigger types
  RegistrationDateUtc  Task registration date (RegistrationInfo Date,
                       recorded in the system's local time); blank if not set
  LastRunTimeUtc       Blank if the task never ran
  NextRunTimeUtc       Blank if nothing is scheduled
  LastTaskResult       Result code of the last run (decimal; 0 = success,
                       267011 = has not run yet)

Disabled tasks are included (State = Disabled). On mounted images the task
XML files are collected instead (Persistence\ScheduledTasks_XML\).

### Persistence\services.csv and drivers.csv  (live system only)

Same columns as before plus KeyLastWriteUtc: last-write time of
HKLM\SYSTEM\CurrentControlSet\Services\<Name>. A recent time can point to a
newly installed or changed service or driver, but Windows also updates these
keys during normal operation (updates, start type changes), so treat it as a
lead, not proof.

### Persistence\run_keys.csv  (live system only)

  Hive                 "HKLM" or "HKU\<SID>"
  User                 Account name for HKU rows (blank for HKLM)
  KeyPath              Path relative to the hive, e.g.
                       SOFTWARE\Microsoft\Windows\CurrentVersion\Run
  ValueName            Value name ("(Default)" for the default value)
  Command              Value data as stored (environment variables such as
                       %USERPROFILE% are not expanded)
  KeyLastWriteUtc      Last-write time of the key (the whole key, not the
                       single value)

Keys covered, for HKLM and for every loaded user hive (local and Entra ID
accounts): Run, RunOnce, WOW6432Node Run/RunOnce, Policies\Explorer\Run.
run_keys.txt lists the same keys plus Shell Folders / User Shell Folders.

### Persistence\startup_folders.csv  (live system and mounted images)

  Scope                "AllUsers" or "User"
  User                 Profile folder name (blank for AllUsers)
  Folder               Full path of the Startup folder
  Name                 File or folder name (desktop.ini skipped)
  CreatedUtc           Created time of the item
  ModifiedUtc          Modified time of the item

### USB\usb_storage_devices.csv  (live system only)

  FriendlyName         e.g. "PNY USB 3.1 FD USB Device"
  InstanceId           USBSTOR\DISK&VEN_...&PROD_...&REV_...\<serial>&0
  Serial               Last part of the instance ID without the "&0" suffix
                       (if its second character is "&", Windows generated it
                       because the device reports no serial number)
  FirstInstallUtc      First time the device was installed on this system
  InstallUtc           Last (re)install time
  LastArrivalUtc       Last time the device was connected
  LastRemovalUtc       Last time the device was removed

Devices that are no longer connected are included.


## Analyzing the Output

### With win11-timeline-builder (recommended)

The fastest path from collection to analysis:

  1. Double-click Run-TimelineBuilder.bat (no arguments needed)
  2. It auto-finds triage zips in the sibling reports\ directory
  3. Pick a collection number
  4. If a memory dump is detected alongside the zip and Volatility 3 is
     installed, the script prompts to include memory analysis
  5. Timeline builds (~2 minutes for ~56,000 events, longer with memory)
  6. Color-coded Excel (.xlsx) is generated with rows colored by EventType
  7. Choose a viewer: Excel (colored), Timeline Explorer, Both, or None
  8. Filter, sort, pivot, investigate

  The timeline builder produces both CSV (full data) and Excel (color-coded).
  It parses only the triage collection data -- never queries the local system.

  Companion project: https://github.com/Jumbalicious79/win11-timeline-builder

### With Eric Zimmerman's Tools (manual deep-dive)

  MFTECmd.exe -f "Collection\FileSystem\$MFT" --csv ".\parsed" --csvf mft.csv
  MFTECmd.exe -f "Collection\FileSystem\$UsnJrnl_$J" -m "Collection\FileSystem\$MFT" --csv ".\parsed" --csvf usn.csv
  PECmd.exe -d "Collection\Execution\Prefetch" --csv ".\parsed" --csvf prefetch.csv
  EvtxECmd.exe -d "Collection\EventLogs" --csv ".\parsed" --csvf evtx.csv
  RECmd.exe --bn BatchExamples\RECmd_Batch_MC.reb -d "Collection\Registry" --csv ".\parsed"
  AmcacheParser.exe -f "Collection\Registry\Amcache.hve" --csv ".\parsed"

  Download EZ Tools: https://ericzimmerman.github.io/


## What This Script Does NOT Do

  - No analysis -- collection only. Use timeline-builder for analysis.
  - No network capture -- use Wireshark or "netsh trace" for packets.
  - No memory dump by default -- enable by placing a capture tool in tools\
    (see Optional Tools section). When enabled, memory capture runs first.
  - No disk imaging -- collects specific artifacts, not a full image.
    For a full image, use FTK Imager or dd.
  - No malware scanning -- does not identify or classify malware.
  - No cloud artifacts -- OneDrive, Teams, cloud data not collected.
  - No remediation -- does not remove, quarantine, or modify anything.


## Known Limitations and Expected Warnings

  - $MFT, $LogFile and $UsnJrnl:$J are read raw from the volume. On a live
    system they are copied while Windows keeps changing them, so they are a
    near point-in-time snapshot, not an atomic one (the same holds for other
    live raw-copy tools). The raw copies are skipped (logged, collection goes
    on) when the volume cannot be opened (e.g., blocked by endpoint security),
    when the target is not an NTFS volume, or for nested image layouts such
    as E:\C\Windows -- mount the image so the volume itself has a drive
    letter to get them.
    Warning: "Raw $MFT, $LogFile and $UsnJrnl:$J not collected: cannot open \\.\C: (...)"

  - Very large volumes (millions of files) can have a $MFT over 2 GB. If the
    zip step fails on it, the uncompressed collection folder is kept (see the
    log); run with -NoCompress and compress with another tool in that case.

  - Per-user live registry data (Run/RunOnce keys, RecentApps) covers every
    user whose hive is loaded, i.e. users logged in at collection time, not
    only the account running the collector. For users who are not logged in,
    the same keys are in their NTUSER.DAT under Registry\<user>\.

  - The temporary Defender exclusion and the shadow copy are removed even if
    the run is stopped with Ctrl+C or ends with an error. If the console
    window is closed or the machine loses power mid-run, cleanup may not get
    to run: check Windows Security exclusions and "vssadmin list shadows".

  - Locked files (live system): when a normal copy fails because a program
    has the file open, the script tries, in order:
      1. the Volume Shadow Copy (point-in-time snapshot, made on first need)
      2. a raw NTFS read: the file is looked up in the $MFT (a name index
         built on first use, a few seconds) and its data is read straight
         from the volume, which file locks don't prevent. Used for files the
         shadow copy can't provide -- created after the snapshot was taken,
         or no snapshot possible on that machine.
    A raw read is not a point-in-time snapshot: a file being written during
    the read can come out inconsistent. NTFS-compressed and EFS-encrypted
    files cannot be read this way. Empty files are skipped (there is nothing
    to collect; Chromium browsers keep 0-byte SQLite journals open).
    Log: "Collected by raw NTFS read (file in use, not available from a
    shadow copy)"

  - NTUSER.DAT and UsrClass.dat for the active user are locked. The script
    tries reg save via HKU\SID (works for logged-in users), then VSS shadow
    copy, then direct copy. On most systems reg save succeeds.

  - System service accounts (e.g., WsiAccount) may have locked or inaccessible
    hive files. Shadow copy attempts will fail for these. This is normal --
    these are not real user accounts and contain minimal forensic data.
    Warning: "Shadow copy of Users\WsiAccount\NTUSER.DAT did not produce output"

  - Hidden files are collected, including the Amcache.hve transaction logs
    (.LOG1/.LOG2) and the hidden NTUSER.DAT / UsrClass.dat of users who are
    not logged in. Folder listings of artifacts (Prefetch, Recent LNK files,
    jump lists, browser profiles, scheduled task XML, Defender and
    third-party AV logs) include hidden and system files. (Earlier versions
    skipped those in listings, and copied hidden files and then deleted
    them as "empty".) Locked Amcache logs are taken from the shadow copy or
    by raw NTFS read; if the hive is still dirty without its logs, the
    timeline builder skips Amcache parsing for that collection.

  - A file is reported as not collected only when the normal copy, the
    shadow copy and the raw NTFS read all fail.
    Warning: "Could not copy (locked; shadow copy and raw NTFS read also failed)"

  - Sysmon and Task Scheduler logs only collected if present on the system.
    These are not installed by default on Windows 11 Home.
    Message: "Skipping Microsoft-Windows-Sysmon%4Operational.evtx (not present)"

  - The collection manifest hashes are computed on destination copies, not source
    files. For "reg save" exports, the hash represents the saved snapshot.


## Legal and Authorization

IMPORTANT: Only run this script on systems you are authorized to examine.

  - Obtain written authorization before collecting forensic artifacts.
  - This script accesses sensitive data including password databases (SAM),
    security policies, browser credentials, and user activity history.
  - Collected artifacts may contain PII subject to privacy regulations.
  - Maintain chain of custody documentation if used in legal proceedings.
  - The collection manifest provides SHA256 hashes for integrity verification.
  - Store collected data securely. Limit access to authorized personnel.
  - The script temporarily manages a Windows Defender exclusion (logged).

For legal cases, create a forensic image FIRST, then run this script against
the mounted image for a non-invasive collection.


## Parameters

  -TargetDrive     Single drive letter to collect from (e.g., C, E, F).
                   Default: system drive (usually C).
                   Use this to collect from a mounted forensic image.
                   The script auto-detects live vs mounted and adjusts
                   collection methods accordingly.
  -OutputPath      Where to save collected artifacts.
                   Default: reports\TriageCollection_<timestamp>
  -SkipLargeFiles  Skip the raw NTFS copies ($MFT, $LogFile, $UsnJrnl:$J)
                   and the fsutil USN journal export for faster, smaller
                   runs ("fast" in the .bat). These are the timeline
                   builder's largest sources. Registry hives are still
                   collected.
  -NoCompress      Keep uncompressed folder (don't zip and delete).
  -Categories      Specific categories to collect. Default: all (except Memory).
                   Valid: Memory, FileSystem, Registry, EventLogs, Execution,
                   Network, UserActivity, Browser, USB, Persistence,
                   AntiVirus
                   Note: Memory is opt-in. On live systems, the script prompts
                   if a capture tool is found in tools\. For automation, pass
                   -Categories "Memory","FileSystem","Registry",...


## Optional Tools (tools\ directory)

The script supports optional third-party tools for capabilities that require
kernel-mode access (e.g., memory capture). These tools are NOT included in
the repo -- their licenses don't allow redistribution, so you download and
place them yourself. The repo ships each expected tool folder with a
README.txt (download link and layout); git ignores everything else in tools\,
so a downloaded tool is never committed.

  win11-triage-collector\
    tools\
      dumpit\                      <-- in the repo: README.txt only
        README.txt                 <-- where to get DumpIt and how it's used
        ARM64\DumpIt.exe           <-- you add these (extract the download)
        x64\DumpIt.exe
        x86\DumpIt.exe

Each tool gets its own subfolder, matching the timeline builder's layout.
Tools placed here travel with the script on USB drives. If a tool is not
present, the script skips that capability and continues normally.


### Memory Capture Setup

Memory capture requires a kernel-mode driver to read physical RAM. The
script auto-detects supported tools in the tools\ directory. On a live
system, if a tool is found, the script prompts you to include memory
capture before collection begins.

  Recommended: Magnet DumpIt (free, signed; native x86, x64 and ARM64)
    1. Request it (registration form; the link arrives by email):
       https://www.magnetforensics.com/resources/magnet-dumpit-for-windows/
    2. Extract the download into win11-triage-collector\tools\dumpit\ as-is
       (tools\dumpit\ARM64\DumpIt.exe, tools\dumpit\x64\DumpIt.exe, ...)
    The script runs the build that matches the CPU, with
    /TYPE DMP /NOCOMPRESS /QUIET, producing a Microsoft crash dump.
    Details: tools\dumpit\README.txt

  Alternative: WinPmem (open-source, signed driver; x86/x64 only)
    1. Download from: https://github.com/Velocidex/WinPmem/releases
    2. Download the latest winpmem_mini_x64.exe (or winpmem_x64.exe)
    3. Rename to winpmem.exe
    4. Place in: win11-triage-collector\tools\winpmem\winpmem.exe

  Alternative: Magnet RAM Capture (Magnet Forensics, free; x86/x64 only)
    1. Download from: https://www.magnetforensics.com/resources/magnet-ram-capture/
    2. Place in: win11-triage-collector\tools\magnetram\MagnetRAMCapture.exe

  Tool priority: If multiple tools are present, the script uses the first
  one found in this order: DumpIt > WinPmem > Magnet RAM Capture.

  Windows on ARM: a capture tool loads a kernel driver, and x64 drivers don't
  load on ARM64 Windows. On ARM64 the script only uses ARM64 builds (DumpIt)
  and skips the others with a note.

  Output: Memory\memory_dump.dmp (DumpIt) or memory_dump.raw, saved next to
          the zip as <collection>_memory_dump.dmp / .raw
  Storage: Dump size equals installed RAM (16 GB RAM = ~16 GB file).
           Ensure the output drive has enough free space.
  Timing: Adds 2-5 minutes depending on RAM size.
  Ordering: Runs FIRST to capture pristine RAM before other collection.
  Live only: Memory capture is skipped for mounted forensic images.
  Analysis: win11-timeline-builder analyzes x64 dumps with Volatility 3.
            Volatility 3 cannot analyze Windows ARM64 memory; open ARM64
            dumps in WinDbg instead.

  If no tool is found in tools\, the script does not prompt and proceeds
  with standard artifact collection. No errors, no noise.


## Tests

  tests\Test-RawCopy.ps1 (run as Administrator; also runs in CI)
    Creates test files on the system drive, locks them so a normal copy
    fails, and checks that the collector still collects them byte for byte
    by reading the volume directly (the fallback after the shadow copy):
    files in clusters and inside the MFT record, a non-ASCII name, a sparse
    file, a file extended past its written data, and an NTFS-compressed
    file, which the raw read must decline cleanly.

  Planted-activity test (both tools, end to end, on a live machine)
    1. In a normal (not elevated) PowerShell window, as the user to test:
         powershell -ExecutionPolicy Bypass -File tests\Invoke-PlantedActivity.ps1
       It does harmless, recognizable actions, all named TriageE2E_<id>: runs
       a renamed copy of hostname.exe, backdates (timestomps) another copy,
       adds a file to Recent items, creates and deletes a file, adds a Run
       value and a disabled scheduled task, and opens an Edge page.
       -Eicar also writes the EICAR antivirus test file (Defender detects
       and quarantines it); -NoBrowser skips Edge.
    2. Run-TriageCollector.bat, then Run-TimelineBuilder.bat on the new
       collection (win11-timeline-builder next to this repository).
    3. powershell -ExecutionPolicy Bypass -File tests\Test-PlantedActivity.ps1
       Finds each action in the timeline by source and time. Required checks
       fail the test; best-effort ones (BAM, Amcache, ShimCache, UserAssist,
       jump list, deleted MFT record) depend on when Windows writes them and
       are only reported. Restart before collecting to get ShimCache.
    4. powershell -ExecutionPolicy Bypass -File tests\Invoke-PlantedActivity.ps1 -Cleanup
       Removes the Run value, the task, the Recent shortcut and the files.


## Requirements

  - Windows 10 or Windows 11
  - PowerShell 5.1 or later (built into Windows)
  - Administrator privileges (the .bat launcher handles elevation)
  - No external dependencies -- no binaries to download or install


## Windows Built-In Tools Used

This script uses only tools that ship with Windows. No third-party binaries
are downloaded, bundled, or required.

  fsutil.exe           Exports the USN Journal ($UsnJrnl:$J) as CSV-style
                       text ($UsnJrnl_$J.txt), next to the raw copy.
                       Ships with all Windows versions.

  reg.exe              Exports registry hives (SYSTEM, SOFTWARE, SAM,
                       SECURITY) via "reg save". Produces clean hive copies
                       without requiring VSS. Ships with all Windows versions.

  wevtutil.exe         Exports event log files (.evtx) from the live system.
                       Handles locked log files properly.
                       Ships with all Windows versions.

  vssadmin.exe /       Creates and removes Volume Shadow Copy snapshots for
  Win32_ShadowCopy     accessing locked files (NTUSER.DAT, browser
                       databases, etc.).
                       Uses WMI Win32_ShadowCopy class via PowerShell.

  robocopy.exe         Not used. Considered but requires Backup privileges
                       not available on Windows 11 Home.

  PowerShell cmdlets   Get-CimInstance (WMI queries), Get-ScheduledTask,
                       Get-ScheduledTaskInfo (task run times),
                       Get-PnpDevice / Get-PnpDeviceProperty (USB device
                       install/arrival/removal times),
                       Get-NetTCPConnection, Get-DnsClientCache,
                       Get-NetFirewallRule, Add/Remove-MpPreference
                       (Defender exclusion management).

  RegQueryInfoKey      Windows API (advapi32.dll), called through a small
  (Add-Type)           Add-Type definition to read registry key last-write
                       times (services, drivers, Run keys).

  Raw NTFS reader      Built into the script (C# compiled via Add-Type). Opens
  (CreateFile,         the volume (\\.\C:) read-only with the kernel32.dll
  Add-Type)            CreateFile API and reads $MFT, $LogFile and
                       $UsnJrnl:$J from the NTFS structures directly.


## Credits and Acknowledgments

  Buzz Hillestad,      Design, testing, forensic workflow, and artifact
  GCFE                 selection. Defined the collection categories, triage
                       methodology, USB deployment workflow, and integration
                       with the win11-timeline-builder companion project.

  Claude Code          Code generation and implementation. All PowerShell
  (Anthropic)          scripts, batch launchers, and supporting code were
                       written by Claude Code (claude.ai/code).

  Eric Zimmerman       This script's output is designed to be parsed by Eric
                       Zimmerman's forensic tools (EZ Tools) and by the
                       companion win11-timeline-builder project.
                       EZ Tools: https://ericzimmerman.github.io/

  Velocidex /          WinPmem is an open-source memory acquisition tool
  WinPmem              with a signed kernel driver. Optionally used for
                       live RAM capture when placed in the tools\ directory.
                       https://github.com/Velocidex/WinPmem

  Magnet Forensics     DumpIt (the preferred capture tool, with native
                       x86/x64/ARM64 builds) and Magnet RAM Capture are free
                       memory acquisition tools, used when placed in the
                       tools\ directory. Not redistributed with this repo.
                       https://www.magnetforensics.com/

  KAPE                 The artifa

Read the rest on GitHub

Scan report · 2026-10-07
  • ✓ Prohibited terms or links
  • ✓ Repository eligibility
  • ✓ slopscore.md paperwork
  • ✓ Content policy
  • ✓ Risk review — +25 binaries at repo root (Run-TriageCollector.bat, triage-collector.ps1)

From the balcony · 3 of 4 clapped

  1. Princessclapped
    Clear forensic tool with working status, MIT license, documented setup, tested on real systems, and a functional companion project integration.
  2. Crusoeclapped
    Dependency-free forensic tool with no vulnerable dependencies, clear local-only data collection story, and no credential requests.
  3. Cap'm Slopclapped
    README clearly explains what it does (forensic artifact collection), how to run it (PowerShell script with setup instructions), how it was made (mostly AI-generated with light human touch), includes t

Schnitzel read it and passed. Their reasons are on the balcony, with every other verdict.

Critics are accounts on this site with no GitHub account behind them. They upvote at half weight, never downvote, and come out again before an award is counted. Who they are.

0 comments

log in to comment.

report this listing — log in to report