LogoLogo
CtrlK
Back to binalyze.com
  • AIR Knowledge Base
  • AIR
    • AIR Platform
      • What is AIR?
      • Terminology
      • Architecture
        • AIR Responder Architecture; overview and performance analysis
        • AIR Task Flow and Management
      • Network Communication
      • Cloud Forensics
    • Setup
      • Relay Server
        • What is Relay Server?
        • Requirements for installation
        • How to install a Relay Server on different Linux platforms
        • How to change IP address of Relay Server
        • How to install a Responder with Relay Server support
        • Proxy configurations
          • Adding proxy to Relay Server
          • Adding proxy to Responder
        • Service Management for Relay Server
        • Whitelisting for Relay Server
        • Retrieving metrics from Relay Server
        • Updating and Uninstalling Relay Server
        • Troubleshooting
      • Responder
        • Responder Hardware Requirements
        • Responder - Supported Operating Systems
          • Responder - MS Windows supported systems
          • Responder - Apple macOS supported systems
          • Responder - Linux (DEB/RPM) supported systems
          • ESXi Standalone Collector
          • Responder - Chrome supported systems
            • AIR For Chrome
        • Responder for Golden Images
        • Responder and Active Directory OUs
        • Responder Exception Rules
          • AIR Watchdog Folder
        • FDA via Jamf and Apple's PPPC utility
        • Responder in Windows Safe Mode
      • Security
        • Two-factor authentication (2FA)
    • Settings
      • Console Settings
        • General
        • Assets
        • Security
        • Features
        • Evidence Repositories
        • Policies
        • User Management
          • User Groups
          • User Roles
        • Backup
        • Investigation Hub Disk Usage
        • Danger Zone
      • Organization Settings
      • Account Settings
    • Updating
      • Console Updating - SaaS
    • Features
      • API
        • API is likely to be more effective than Webhooks
      • Asset Isolation
      • Acquisition
        • Acquisition Profiles
          • Supported Evidence
          • ESXi Collections
            • Account Info
            • Active Connections
            • Advanced Config
            • Advanced Settings
            • Case Info
            • Collection Info
            • CPU Info
            • Datastores
            • Disk Usage
            • Environment Variables
            • File System Info
            • Firewall Ruleset
            • Hardware Clock
            • IP Interface Info
            • Kernel Info
            • Module List
            • Multipathing Info
            • Networks
            • NIC List
            • Open Files
            • PCI Info
            • Permission Info
            • Process
            • Routes
            • Routing Table
            • SCSI Info
            • Security Policy Domain
            • Syslog Config
            • Syslog Logger Info
            • System Info
            • User Info
            • VIB Info
            • Virtual Switch Info
            • VMkernel NIC List
            • WBEM Info
          • IBM AIX Collections
            • Artifacts
            • Browser Bookmarks
            • Browser Cookies
            • Browser Downloads
            • Browser Favicons
            • Browser Form History
            • Browser History
            • Browser Indexed DB
            • Browser Local Storage
            • Browser Login Data
            • Browser Sessions
            • Browser Thumbnails
            • Browser User Profiles
            • Browser Web Storage
            • Cron Jobs
            • Default Browser
            • DNS Resolvers
            • Docker Changes
            • Docker Container Logs
            • Docker Containers
            • Docker Image History
            • Docker Images
            • Docker Info
            • Docker Networks
            • Docker Tops
            • Docker Volumes
            • File System Enumeration
            • Firefox Cookies
            • Firefox Extensions
            • Hosts
            • Info
            • Log Files
            • Mounts
            • Process
            • Shell History
            • SSH Authorized Keys
            • SSH Configs
            • SSH Known Hosts
            • SSHD Configs
            • SUID Binaries
            • System Artifacts
            • System
            • ULimit Info
            • User Groups
            • Users
            • YUM History
            • YUM Sources
          • Linux Collections
            • System Controls
            • Cron Jobs
            • AppArmor Profiles
            • ULimit Info
            • Kernel Modules
            • Lock Files
            • Systemctl
            • Block Devices
            • Fstab
            • Mounts
            • NFS Exports
            • File System Enumeration
            • Processes
            • Process Open Files
            • Shared Memory
            • Memory Map
            • Swaps
            • RAM Image
            • Default Browser
            • Chrome Cookies
            • Chromium Cookies
            • Edge Cookies
            • Opera Cookies
            • Vivaldi Cookies
            • Brave Cookies
            • Chrome Bookmarks
            • Chromium Bookmarks
            • Edge Bookmarks
            • Opera Bookmarks
            • Vivaldi Bookmarks
            • Brave Bookmarks
            • Chrome User Profiles
            • Chromium User Profiles
            • Edge User Profiles
            • Opera User Profiles
            • Vivaldi User Profiles
            • Brave User Profiles
            • Chrome Extensions
            • Firefox Extensions
            • Chrome Local Storage
            • Chromium Local Storage
            • Edge Local Storage
            • Opera Local Storage
            • Vivaldi Local Storage
            • Brave Local Storage
            • Dump Chrome Indexed DB
            • Dump Chromium Indexed DB
            • Dump Edge Indexed DB
            • Dump Opera Indexed DB
            • Dump Vivaldi Indexed DB
            • Dump Brave Indexed DB
            • Chrome Web Storage
            • Chromium Web Storage
            • Edge Web Storage
            • Opera Web Storage
            • Vivaldi Web Storage
            • Brave Web Storage
            • Chrome Form History
            • Chromium Form History
            • Edge Form History
            • Opera Form History
            • Vivaldi Form History
            • Brave Form History
            • Chrome Thumbnails
            • Chromium Thumbnails
            • Edge Thumbnails
            • Opera Thumbnails
            • Vivaldi Thumbnails
            • Brave Thumbnails
            • Chrome Favicons
            • Chromium Favicons
            • Edge Favicons
            • Opera Favicons
            • Vivaldi Favicons
            • Brave Favicons
            • Chrome Login Data
            • Chromium Login Data
            • Edge Login Data
            • Opera Login Data
            • Vivaldi Login Data
            • Brave Login Data
            • Chrome Sessions
            • Chromium Sessions
            • Brave Sessions
            • Edge Sessions
            • Opera Sessions
            • Vivaldi Sessions
            • Chrome Browsing History
            • Firefox Browsing History
            • Chromium Browsing History
            • Edge Browsing History
            • Opera Browsing History
            • Vivaldi Browsing History
            • Brave Browsing History
            • Chrome Downloads
            • Chromium Downloads
            • Firefox Downloads
            • Brave Downloads
            • Edge Downloads
            • Opera Downloads
            • DEB Packages
            • APT Sources
            • APT History
            • YUM Sources
            • YUM History
            • SELinux Configs
            • SELinux Settings
            • SUID Binaries
            • Shell History
            • System Artifacts
            • Log Files
            • Hosts
            • ICMP Table
            • IP Routes
            • IP Tables
            • Raw Table
            • Network Interfaces
            • TCP Table
            • UDPLite Table
            • UDP Table
            • Unix Sockets
            • ARP Table
          • macOS Collections
            • AnyDesk Logs
            • Apache Logs
            • Apple Audit Logs
            • Apple System Logs
            • Application Usage
            • Arc Bookmarks
            • Arc Browsing History
            • Arc Cookies
            • Arc Downloads
            • Arc Favicons
            • Arc Form History
            • Arc Local Storage
            • Arc Login Data
            • Arc Sessions
            • Arc Thumbnails
            • Arc User Profiles
            • Arc Web Storage
            • Artifacts
            • Auto Loaded Processes
            • Block Devices
            • Bluetooth Connections
            • Brave Bookmarks
            • Brave Browsing History
            • Brave Cookies
            • Brave Downloads
            • Brave Favicons
            • Brave Form History
            • Brave Local Storage
            • Brave Login Data
            • Brave Sessions
            • Brave Thumbnails
            • Brave User Profiles
            • Brave Web Storage
            • Chrome Bookmarks
            • Chrome Browsing History
            • Chrome Cookies
            • Chrome Downloads
            • Chrome Extensions
            • Chrome Favicons
            • Chrome Form History
            • Chrome Local Storage
            • Chrome Login Data
            • Chrome Sessions
            • Chrome Thumbnails
            • Chrome User Profiles
            • Chrome Web Storage
            • Command Line Activity
            • Crashes
            • Cron Jobs
            • Default Browser
            • DHCP Settings
            • Discord Desktop Cache
            • Disk Encryption
            • DMG File Opened
            • DNS Resolvers
            • Dock Items
            • Docker Changes
            • Docker Container Logs
            • Docker Containers
            • Docker Image History
            • Docker Images
            • Docker Info
            • Docker Logs
            • Docker Networks
            • Docker Tops
            • Docker Volumes
            • Document Revisions
            • Downloaded Files Information
            • DS_Store
            • Dump Arc Indexed DB
            • Dump Brave Indexed DB
            • Dump Chrome Indexed DB
            • Dump Edge Indexed DB
            • Dump Opera Indexed DB
            • Dump QQ Indexed DB
            • Dump Vivaldi Indexed DB
            • Edge Bookmarks
            • Edge Browsing History
            • Edge Cookies
            • Edge Download History
            • Edge Extensions
            • Edge Favicons
            • Edge Form History
            • Edge Local Storage
            • Edge Login Data
            • Edge Sessions
            • Edge Thumbnails
            • Edge User Profiles
            • Edge Web Storage
            • Emond Clients
            • Etc Files
            • Etc Hosts
            • Etc Protocols
            • Etc Services
            • Event Taps
            • Failed Sudo
            • File Last Used
            • File System Enumeration
            • Finder Mounted Volume
            • Firefox Browsing History
            • Firefox Cookies
            • Firefox Downloads
            • Firefox Extensions
            • FS Events Collector
            • FS Events Parser
            • Gatekeeper Approved Apps
            • Gatekeeper
            • Homebrew Logs
            • iMessage
            • Install Logs
            • Installed Applications
            • IP Routes
            • Kernel Extensions Info
            • Kernel Extensions
            • Keyboard Dictionary
            • Keychain
            • KnowledgeC Database
            • Launchd Files
            • Launchd Overrides
            • Listening Ports
            • Logged Users
            • Login Hooks
            • Login Items
            • logind
            • Logout Hooks
            • Mail Rules
            • Manuel Configuration Profile Install
            • MongoDB Logs
            • Most Recently Used
            • Mount
            • MySQL Logs
            • Network Capture
            • Network Interfaces
            • Network Usage
            • NetworkFlow
            • NGINX Logs
            • Notification Info
            • Opera Bookmarks
            • Opera Browsing History
            • Opera Cookies
            • Opera Downloads
            • Opera Extensions
            • Opera Favicons
            • Opera Form History
            • Opera Local Storage
            • Opera Login Data
            • Opera Sessions
            • Opera Thumbnails
            • Opera User Profiles
            • Opera Web Storage
            • Package Install History
            • Parallels Logs
            • PCAP
            • PostgreSQL Logs
            • Print Jobs
            • Printer Info
            • Processes
            • QQ Bookmarks
            • QQ Browsing History
            • QQ Cookies
            • QQ Downloads
            • QQ Favicons
            • QQ Form History
            • QQ Local Storage
            • QQ Login Data
            • QQ Sessions
            • QQ Thumbnails
            • QQ User Profiles
            • QQ Web Storage
            • Quarantine Events
            • Quick Look Cache
            • Re-opened Apps
            • Safari Browsing History
            • Safari Downloads
            • ScreenSharing
            • Session Creation and Destruction
            • Shared File List
            • Shell History
            • Software Update Information
            • Sophos Events Database
            • Sophos Logs
            • Splashtop Mac Logs
            • SSH Authorized Keys
            • SSH Configs
            • SSH Files
            • SSH Known Hosts
            • SSHD Configs
            • SSHD
            • Sudo Last Run
            • System Extension Info
            • System Integrity Protection Status
            • System Logs
            • TCCD
            • TeamViewer Logs
            • Transparency, Consent, and Control (TCC)
            • Trash Files
            • User Groups
            • Users
            • Vivaldi Bookmarks
            • Vivaldi Browsing History
            • Vivaldi Cookies
            • Vivaldi Downloads
            • Vivaldi Favicons
            • Vivaldi Form History
            • Vivaldi Local Storage
            • Vivaldi Login Data
            • Vivaldi Sessions
            • Vivaldi Thumbnails
            • Vivaldi User Profiles
            • Vivaldi Web Storage
            • Waterfox Browsing History
            • Waterfox Downloads
            • WiFi Logs
            • Wireless Network Connection Collector
            • XProtect Remediation
          • Windows Collections
            • $Boot
            • $LogFile
            • $Secure:$SDS
            • $TxfLog $Tops:$T
            • ARP Table
            • Active Script Event Consumers
            • Amcache
            • Antivirus Information
            • AppCompatCache
            • AppPaths
            • Artifacts
            • Browser Extensions
            • CIDSizeMRU
            • CLR Logs
            • Chrome Bookmarks
            • Chrome Browsing History
            • Chrome Cookies
            • Chrome Downloads
            • Chrome Extensions
            • Chrome Favicons
            • Chrome Form History
            • Chrome Local Storage
            • Chrome Login Data
            • Chrome Sessions
            • Chrome Thumbnails
            • Chrome User Profiles
            • Chrome Web Storage
            • Clipboard
            • Command Line Event Consumers
            • Crash Dump Information
            • DNS Cache
            • DNS Servers
            • Default Browser
            • Docker Changes
            • Docker Container Logs
            • Docker Containers
            • Docker Image History
            • Docker Images
            • Docker Info
            • Docker Logs
            • Docker Networks
            • Docker Tops
            • Docker Volumes
            • Downloaded Files Information
            • Driver Objects
            • Drivers List
            • ETL Logs
            • Edge Bookmarks
            • Edge Browsing History
            • Edge Cookies
            • Edge Downloads
            • Edge Extensions
            • Edge Favicons
            • Edge Form History
            • Edge Local Storage
            • Edge Login Data
            • Edge Sessions
            • Edge Thumbnails
            • Edge User Profiles
            • Edge Web Storage
            • Environment Variables
            • Event Logs
            • EventTranscript DB
            • FileExts
            • Firefox Browsing History
            • Firefox Cookies
            • Firefox Downloads
            • Firefox Extensions
            • Firewall Rules
            • FirstFolder
            • Hibernation File
            • Hosts File
            • IE 10-11 & Edge Browsing History
            • IE 7-8-9 Browsing History
            • INF Setup Logs
            • IPv4 Routes
            • Iconcache
            • Installed Applications
            • Jumplist
            • LastVisitedPidlMRU
            • Lnk Files
            • MFT (Binary)
            • MFT Mirror
            • MFT as CSV
            • Map Network Drive MRU
            • Master Boot Record (MBR)
            • NTDS.dit
            • Network Adapters
            • Network Capture
            • Network Shares
            • Object Directory
            • OfficeMRU
            • Old Registry Hives
            • OpenSavePidlMRU
            • PDB Information
            • Page File
            • PowerShell Logs
            • Powershell History
            • Prefetch Files
            • Processes and Modules
            • Proxy Information
            • Quick Assist
            • RAM Image
            • RDP Cache Files
            • RecentDocs
            • RecentFileCache.bcf
            • Recycle Bin Information
            • Registry Hives
            • Registry Items
            • Registry Persistence
            • RunMRU
            • SRUM
            • Sam
            • Scheduled Tasks
            • Service List
            • Shadow Copy as CSV
            • ShellBags
            • ShellFolders
            • Shim Database
            • Startup Items
            • Superfetch
            • Swap File
            • System Restore Points Information
            • TCP Table
            • Thumbcache
            • Timeline
            • TypedPaths
            • TypedURLs
            • UDP Table
            • USB Storage History
            • USN Journal $Max
            • USN Journal (Binary)
            • USN Journal as CSV
            • Ual
            • User Folders
            • UserAssist
            • Users
            • Volume Information
            • WBEM Files
            • Window Screenshots
            • Windows Index Search
            • Winrar
            • Wireless History
            • WordWheelQuery
            • Windows Collections Detail
        • Chain Of Custody
        • Disk and Volume Imaging
          • Imaging with interACT
        • Scheduling Tasks
        • Task Creation
          • Asset Management with Persistent Saved Filters
          • Regex in DRONE:
          • Task Cancellation and Deletion
      • Auto Tagging & Tags
        • Tags
      • Compare
      • Console Audit Logs
      • DRONE
        • Analyzers
          • Cross Platform Analyzers
            • Browser History Analyzer
            • Dynamo Analyzer
            • Generic WebShell Analyzer
            • MITRE ATT&CK Analyzer
              • MITRE ATT&CK Analyzer changelog
          • Linux Analyzers
          • macOS Analyzers
            • Audit Event Analyzer
          • Windows Analyzers
            • Prefetch Analyzer
            • Shellbag Data Fields
            • Windows Event Records and how they are handled
              • Event Records Summary vs. Event Records
              • Windows Event Logs in v4.21 and older versions
        • What is an Analysis Pipeline?
        • What is DRONE?
      • Event Subscription
      • Evidence Repositories
        • Generating a SAS URL
      • File Explorer
        • File Explorer - FAQs
      • Fleet AI
      • Integrations
        • Microsoft Azure Cloud Platform Integration
        • SSO Integrations
          • FortiAuthenticator SAML 2.0 SSO Integration
          • Microsoft Azure SSO Integration
          • Okta SAML 2.0 SSO Integration
        • Webhooks
          • Carbon Black Cloud Integration
          • Cisco XDR Integration
          • Cortex XSOAR Integration
          • Crowdstrike Integration
          • Dynatrace Integration
          • Elasticsearch Logstash Kibana Integration
          • Fortigate SIEM Integration
          • IBM QRadar Integration
          • LogicHub SOAR (DEVO) Integration
          • Mattermost Integration
          • Microsoft 365 Defender Integration
          • Microsoft Sentinel Integration
          • Rapid7 InsightIDR Integration
          • SentinelOne Integration
          • ServiceNow Integration
          • Slack Integration
          • Splunk Integration
          • Stellar XDR Integration
          • Sumo Logic Integration
          • Wazuh Integration
      • interACT
        • interACT Commands
        • interACT Command Snippets
        • PowerShell commands in interACT
      • Investigation Hub
        • Investigation Hub – Data Usage Statistics Dashboard
        • Using the Investigation Hub
      • Off-Network Responder
        • biunzip
          • biunzip password file
        • Setting Up a Custom Case Directory
      • Policies
      • Proxy Configuration on the Console
      • Repository Explorer
      • Responder Proxy Support
      • Timeline
      • Tornado (Preview Version)
        • Getting Started with Tornado
          • Tornado Terminology
        • Tornado Collectors
          • Access Modes in O365
            • O365 license types
          • Accessing Google Workspace
            • Service Account Creation
              • Enable Service Account Key Creation
        • Tornado Demo
        • Tornado FAQs
        • Tornado Installation Guide
          • Tornado Operating System Support
        • Tornado Troubleshooting & Feedback
        • Updating Tornado
      • Triage
        • Schedule Triage Tasks
        • Triage Rule Templates
          • Sigma Templates
          • YARA Templates
          • osquery Templates
    • Integrations
      • Microsoft Azure Cloud Platform Integration
      • SSO Integrations
        • Microsoft Azure SSO Integration
        • Okta SAML 2.0 SSO Integration
        • FortiAuthenticator SAML 2.0 SSO Integration
      • Webhooks
        • Mattermost Integration
        • Splunk Integration
        • IBM QRadar Integration
        • Wazuh Integration
        • Cortex XSOAR Integration
        • Elasticsearch Logstash Kibana Integration
        • ServiceNow Integration
        • Sumo Logic Integration
        • Crowdstrike Integration
        • Microsoft Sentinel Integration
        • Slack Integration
        • Carbon Black Cloud Integration
        • Rapid7 InsightIDR Integration
        • LogicHub SOAR (DEVO) Integration
        • Fortigate SIEM Integration
        • Dynatrace Integration
        • Stellar XDR Integration
        • SentinelOne Integration
        • Microsoft 365 Defender Integration
        • Cisco XDR Integration
    • Troubleshooting
      • Understanding MSI Error Code 1618
      • How to gather logs for Troubleshooting
        • Collecting Console Log Files
        • Collecting Responder Log Files
        • Collecting Off-Network Responder Log Files
    • FAQs
      • How to download the collected evidence and artifacts?
      • How to gather logs for Troubleshooting
        • Collecting Console Log Files
        • Collecting Responder Log Files
        • Collecting Off-Network Responder Log Files
      • Responder troubleshooting
      • Understanding Port Usage
      • How many assets can connect to a single Console instance?
      • How do I enable SSL on Console?
      • Can I use AIR with EDR/XDR Products?
      • Can I integrate AIR with my SOAR/SIEM?
      • What external URLs are used?
      • Docker & Host System IP Conflict
      • Monitoring Responder and UI API's
      • How do I update Responders on assets?
      • How to reset the password of a user via the CLI?
      • Is there a way to move an asset from one Organization or Case to another?
      • Creating exclusions/exception rules for Responder on EPP and EDR Solutions
      • Anything missing?
  • Self-Hosted
    • Setup
      • Console Hardware Requirements
      • Pre-Installation Requirements
      • Installation Guide
        • Post-Deployment Configuration Guide
        • Using CLI on Console
      • Security
        • Console Access Control
        • Trust Center: Your Security and Compliance Hub
        • SSL Enforcement
          • SSL Certificate Management
      • Uninstalling Responders
    • Updating
      • 2-Tier Systems
      • Single-Tier Systems
      • Single-Tier Systems
    • Backup
      • Restore Backup Using the CLI
    • FAQs
      • Console Backup Procedure
      • Console CPU Profiling for Performance Issues
      • Console Migration Procedure for 2-Tier Installation
      • Console Migration Procedure for Single-Tier Setup
      • How can I install a version that isn't the latest?
      • How do I update console? * Roadmap
      • Resolving the "Invalid Host Header. Host must be the Console Address" Error
  • General
    • Licenses - Open-Source Software List
Powered by GitBook
On this page

Was this helpful?

  1. AIR

Troubleshooting

https://github.com/binalyze-kb/temp/blob/main/product-platform/troubleshooting/console-cpu-profiling-for-performance-issues.mdUnderstanding MSI Error Code 1618How to gather logs for Troubleshooting
PreviousCisco XDR IntegrationNextUnderstanding MSI Error Code 1618

Last updated 25 days ago

Was this helpful?