SNIPPETS from the Article:-
CrowdResponse is a modular Windows console application designed to aid in the gathering of host information for incident response engagements.
This initial version provides three useful built-in modules
- @dirlist - This is the directory-listing module. This sounds quite simple, but it is actually extremely powerful.
- @pslist - This is the active running process listing module.
- @yara - YARA will be familiar to many as an incredibly useful tool aimed at helping malware researchers identify and classify malware. It can act on files on disk or in-memory process images and runs a set of pattern matching rules against the target of investigation.
The links below has more information:
No comments:
Post a Comment