Home

Awesome

AChoir

Windows Live Artifacts Acquisition Scripting Framework

Brief Description:

Every Incident Responder eventually comes to the conclusion that they need to script their favorite Live Acquisition utilities.

I have seen these scripts written in numerous scripting languages - but oddly enough, all of these scripts tend to use many of the same freely available utilities - To do mostly the same things.

It often takes an Incident Responder several years, along with lots of trial and error to settle on a set of utilities (and options) that both work and that provide relevant information on useful forensic artifacts.

And even though Responders often use the same utilities and are scripting them in largely the same way, each Responder has to go through the same pain of building their own script in their (not so) favorite scripting language - figuring out how to quickly and consistently gather the artifacts of most value.

Achoir is a Framework/Scripting Tool to standardize and simplify that process.

#Versions (So Far):

AChoir v0.01

AChoir v0.02

AChoir v0.03

AChoir v0.04

AChoir v0.05

AChoir v0.06

AChoir v0.07

AChoir v0.08

AChoir v0.09

AChoir v0.10

AChoir v0.11

AChoir v0.13

AChoir v0.20

AChoir v0.21

AChoir v0.22

AChoir v0.23

AChoir v0.24

AChoir v0.25

AChoir v0.26

AChoir v0.27

AChoir v0.28

AChoir v0.29

AChoir v0.30

AChoir v0.31

AChoir v0.32

AChoir v0.33

AChoir v0.34

AChoir v0.35

AChoir v0.36

AChoir v0.37

AChoir v0.38

AChoir v0.39

AChoir v0.40

AChoir v0.41

AChoir v0.42

AChoir v0.43

AChoir v0.44

AChoir v0.50

AChoir v0.55

AChoir v0.56

AChoir v0.57

AChoir v0.75

AChoir v0.80

AChoir v0.81

AChoir v0.82

AChoir v0.83

AChoir v0.85

AChoir v0.89

AChoir v0.90

AChoir v0.91

AChoir v0.92

AChoir v0.93

AChoir v0.95

AChoir v0.96

AChoir v0.96a

AChoir v0.97

AChoir v0.98

AChoir v0.98a

AChoir v1.0

AChoir v1.1

AChoir v1.2

AChoir v1.3

AChoir v1.4

AChoir v1.5

AChoir v1.6

AChoir v1.7

AChoir v1.8

AChoir v1.9

AChoir v1.9a

AChoir v2.0

AChoir v2.1

AChoir v2.2

AChoir v2.3

AChoir v2.4

AChoir v2.5

AChoir v2.6

AChoir v2.7

AChoir v2.8

AChoir v2.9

AChoir v3.0

AChoir v3.1

AChoir v3.2

AChoir v3.3

AChoir v3.4\

AChoir v3.5

AChoir v3.6

AChoir v3.7

AChoir v3.8

AChoir v3.9

AChoir v4.0

AChoir v4.1

AChoir v4.2

AChoir v4.3

AChoir v4.4

AChoir v4.5

Quick Start (tl;dr):

The quickest way to get started with AChoir is to download the Achoir-Inst.exe file, run it, and allow it to build the default AChoir Toolkit.

If you want to buid the toolkit onto an external USB drive, simply install Achoir to your external USB drive, and let the Install program run the build process from there. Achoir will Install and build the toolkit onto the Drive and Directory it is installed to. This process also works if you want to install/run AChoir from a network share.