Perl provides a great deal of power and flexibility for collecting information from Windows systems. Since Perl is an interpreted language, the Perl interpreter needs to be installed on the system or accessible by the scripts via some other means. Using the method described in this appendix, Perl scripts can be copied to a CD and run on any system, even one that does not have Perl installed. Using specifically crafted Perl scripts, the administrator can retrieve information from systems not normally available via other tools.

Get Windows Forensics and Incident Recovery now with O’Reilly online learning.

O’Reilly members experience live online training, plus books, videos, and digital content from 200+ publishers.