CDIR Collector v1.3.1
CDIR Collector v1.3.1 (Digitally Signed)
https://www.cyberdefense.jp/download/cdir-collector_1.3.1.zip
- Imported Pull Request #2
- Added acquisition of registry transaction log (.LOG1 and .LOG2)
- Added acquisition of $SECURE:$SDS, WMI and SRUM
- Added 'SECURE', 'WMI' and 'SRUM' settings in cdir.ini
- Added 'Target' setting for specifying target volume
- Added 'MemoryDumpCmdline' setting for alternative ram dump program
- Moved acquired internal files of NTFS to 'NTFS' directory
Known Limitation
We have received a bug report about evtx acquisition of windows 10 from a number of users. Unfortunately, we can't reproduce this issue on our machines. If you get this kind of error, please create new issue or contact us with details.