Skip to content
DnsLister Forum

Where domain hunters compare notes

OmniTriage: Open-source, zero-dependency Windows live DFIR triage engine in pure Python stdlib (

**Repository:** https://github.com/prox0959/OmniTriage

**License:** MIT

**Platform:** Windows 10/11 / Server

**Dependencies:** Zero (Python standard library only)

### Summary

OmniTriage is a lightweight live digital forensics and incident response (DFIR) triage tool built for rapid evidence collection from a USB drive during endpoint assessments.

Designed to minimize endpoint footprint and eliminate runtime dependency issues during live triage.

### Technical Capabilities:

– **Forensic Execution Artifacts:** Mines AppCompatCache (`ShimCache`) binary structures and decodes ROT13 `UserAssist` keys to reconstruct application execution timelines.

– **Memory & Process Abuse:** Extracts PowerShell ScriptBlock logs (Event ID 4104) and audits anti-forensic log tampering (Event 104/1102).

– **Network & Recon:** Inspects live Windows DNS resolver cache, maps established sockets, and audits RDP terminal service sessions (Event ID 21/24/25).

– **Browser Forensics:** Bypasses file locks to read Chrome, Brave, and Edge SQLite history and download databases.

– **Output:** Produces a portable, standalone dark-themed HTML report in ~0.8 seconds.

Source: r/blueteamsec · by /u/Traditional_Bear5492

Leave a Reply

Your email address will not be published. Required fields are marked *