**Repository:** https://github.com/prox0959/OmniTriage
**License:** MIT
**Platform:** Windows 10/11 / Server
**Dependencies:** Zero (Python standard library only)
### Summary
OmniTriage is a lightweight live digital forensics and incident response (DFIR) triage tool built for rapid evidence collection from a USB drive during endpoint assessments.
Designed to minimize endpoint footprint and eliminate runtime dependency issues during live triage.
### Technical Capabilities:
– **Forensic Execution Artifacts:** Mines AppCompatCache (`ShimCache`) binary structures and decodes ROT13 `UserAssist` keys to reconstruct application execution timelines.
– **Memory & Process Abuse:** Extracts PowerShell ScriptBlock logs (Event ID 4104) and audits anti-forensic log tampering (Event 104/1102).
– **Network & Recon:** Inspects live Windows DNS resolver cache, maps established sockets, and audits RDP terminal service sessions (Event ID 21/24/25).
– **Browser Forensics:** Bypasses file locks to read Chrome, Brave, and Edge SQLite history and download databases.
– **Output:** Produces a portable, standalone dark-themed HTML report in ~0.8 seconds.
Source: r/blueteamsec · by /u/Traditional_Bear5492