Evidence Types
Brief overview to Evidence Types
You can use the command line options for enabling each evidence type separately when Custom collection profile is selected by providing --profile custom option.
Name
Long Form
Short Form
Default
Clipboard
--Clipboard
-clp
TRUE
Crash Dump Info
--CrashDumpInfo
-cdi
TRUE
Recycle Bin Info
--RecycleBinInfo
-rbi
TRUE
Restore Point Info
--RestorePointInfo
-rpi
TRUE
Driver Info
--DriverInfo
-dri
TRUE
Process Info
--ProcessInfo
-pri
TRUE
Screenshots
--Screenshots
-scr
TRUE
AntiVirus Info
--AVInfo
-avi
TRUE
DNS Server
--DNSServer
-dnss
TRUE
Proxy Info
--ProxyInfo
-prxy
TRUE
Downloads Info
--DownloadsInfo
-dli
FALSE
Autoruns
--Autoruns
-aui
TRUE
Installed Apps
--InstalledApps
-apps
TRUE
Firewall Rules
--Firewall
-frwl
TRUE
Volume Info
--VolumeInfo
-voli
TRUE
MBR
--MBR
-mbr
FALSE
RAM
--RAM
-ram
TRUE
PageFile
--PageFile
-pgf
TRUE
SwapFile
--SwapFile
-swp
FALSE
Copy link