Hey everyone,
When arriving at an incident scene with a live Windows endpoint, deploying heavy forensic collection frameworks often requires pre-installed runtimes, creates unnecessary disk noise, or takes several minutes to complete initial triage.
I wanted to see how far I could push pure Python standard library to do rapid, sub-second artifact collection directly from a read-only USB stick without any 3rd-party dependencies (no pip, no external binaries).
### What the collector currently extracts:
-
**Registry & Execution Artifacts:**
– Raw extraction and parsing of locked `NTUSER.dat` hives via Volume Shadow / raw handles.
– ROT13-decoded `UserAssist` and `RunMRU` / `TypedPaths` execution timelines.
– `AppCompatCache` (ShimCache) binary parsing to identify executed binaries even if deleted.
-
**Persistence & Defense Evasion:**
– Audits newly installed services (Event 7045) and security log clearing indicators (Event 104 / 1102).
– Scheduled tasks inspection (`schtasks`).
-
**Network & Web History:**
– Active sockets, listening ports, and live DNS cache inspection (flagging dynamic DNS / staging C2 domains).
– Reading locked Chromium/Chrome/Edge SQLite history without terminating user processes.
It compiles everything into a self-contained, standalone dark-mode HTML report in ~0.8 seconds.
Open-source on GitHub (MIT):
https://github.com/prox0959/OmniTriage
Would love feedback from forensic examiners and examiners who do dead-box vs live triage: What other low-noise registry keys or event logs would you consider essential for a first-minute USB triage script?
Source: r/computerforensics · by /u/Traditional_Bear5492