CyLR.exe
An open source tool that aids responders in this type of acquisition is the CyLR.exe application. This standalone executable, available at https://github.com/orlikoski/CyLR/releases, can be run from a USB or on the system. It is a small application but can acquire a great deal of evidence that can be leveraged as part of the initial investigation or possibly triage. Another key feature of CyLR.exe is its ability to send the data that's been acquired to a remote system either for storage or processing, as we will demonstrate in Chapter 10, Analyzing Log Files.
To acquire the non-volatile log files and other protected files, navigate to the CyLR.exe executable via Command Prompt and run it as administrator. The output directory containing ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access