Skip to content
DnsLister Forum

Where domain hunters compare notes

Built a zero-dependency Python live response triage script for USB responders (parses locked hives, UserAssist, ShimCache in under 1s)

Hey everyone,

When arriving at an incident scene with a live Windows endpoint, deploying heavy forensic collection frameworks often requires pre-installed runtimes, creates unnecessary disk noise, or takes several minutes to complete initial triage.

I wanted to see how far I could push pure Python standard library to do rapid, sub-second artifact collection directly from a read-only USB stick without any 3rd-party dependencies (no pip, no external binaries).

### What the collector currently extracts:

  1. **Registry & Execution Artifacts:**

    – Raw extraction and parsing of locked `NTUSER.dat` hives via Volume Shadow / raw handles.

    – ROT13-decoded `UserAssist` and `RunMRU` / `TypedPaths` execution timelines.

    – `AppCompatCache` (ShimCache) binary parsing to identify executed binaries even if deleted.

  2. **Persistence & Defense Evasion:**

    – Audits newly installed services (Event 7045) and security log clearing indicators (Event 104 / 1102).

    – Scheduled tasks inspection (`schtasks`).

  3. **Network & Web History:**

    – Active sockets, listening ports, and live DNS cache inspection (flagging dynamic DNS / staging C2 domains).

    – Reading locked Chromium/Chrome/Edge SQLite history without terminating user processes.

It compiles everything into a self-contained, standalone dark-mode HTML report in ~0.8 seconds.

Open-source on GitHub (MIT):

https://github.com/prox0959/OmniTriage

Would love feedback from forensic examiners and examiners who do dead-box vs live triage: What other low-noise registry keys or event logs would you consider essential for a first-minute USB triage script?

Source: r/computerforensics · by /u/Traditional_Bear5492

Leave a Reply

Your email address will not be published. Required fields are marked *