MIR-ROR – Motile Incident Response remotely

MIR-ROR: Motile Incident Response – Respond Objectively, Remediate MIR-ROR is a security incident response specialized, command-line script that calls specific Windows SysInternals tools, as well as some other useful tools, to provide live capture data for investigation.

You can easily enhance MIR-ROR to your liking with whatever command line tools you find useful.
For incident response resource, we’ve found it indispensable.
Windows SysInternals licensing prevents us from bundling the tools in a distribution package; you’ll have to retrieve them.

MIR-ROR can be installed on honeypot and detailed logs can be co-related for better co-relation of events and activities on system.

How to use MIR-ROR:

mir-ror.cmd <tool drive letter> <target drive letter>

From where we will refer as the <VICTIM system>, execute:

net use M: //<MIR-ROR server>/IR
Logged on to <VICTIM system>, change directories to the
M: drive.
Execute mir-ror.cmd c m

This will run MIR-ROR against <VICTIM system> but write
the live capture results to <MIR-ROR server> at C:/tools/
MIR-ROR/Livecap_<VICTIM system>.

Pre-requisites:

Windows SysInternals tools
Windows Server 2003 Resource Kit
Seccheck.exe

Operating systems supported:

Windows XP SP2 and above

Download MIR-ROR here

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值