Crow-Eye v0.6.0 Standalone EXE – OUT NOW!
Crow-Eye是一款便携式Windows取证工具,支持多种关键证据类型如Prefetch、Registry、Event Logs等,并生成SQLite数据库、JSON/CSV及HTML报告。 2025-12-7 14:11:26 Author: www.reddit.com(查看原文) 阅读量:0 收藏

Drop this 101MB powerhouse on your USB for instant live Windows forensics. No install, no Python – just run as admin and hunt.

Supported Artifacts:
• Prefetch (exec history, run counts, timestamps)
• Registry (AutoRuns, UserAssist, ShimCache, BAM, networks, time zones)
• Jump Lists & LNK (file access, paths, metadata)
• Event Logs (System/Security/Application)
• Amcache (install time, publisher, full path, file size, volume intro)
• ShimCache (path + last-modified)
• ShellBags (folder views & access history)
• MRU & RecentDocs (typed paths, Open/Save, recent files)
• MFT Parser (file metadata + deleted files)
• USN Journal (create/modify/delete)
• Recycle Bin (original paths + deletion time)
• SRUM (app execution, network & energy usage)

Outputs: Searchable SQLite DBs | JSON/CSV exports | HTML reports for sharing findings.
(Timeline view: prototype – functional but polishing.)

Grab it: https://crow-eye.com/download
GitHub: https://github.com/Ghassan-elsman/Crow-Eye

Bugs? Hit me at [email protected] or open a GitHub issue. Let's make it bulletproof!


文章来源: https://www.reddit.com/r/computerforensics/comments/1pgj9j8/croweye_v060_standalone_exe_out_now/
如有侵权请联系:admin#unsafe.sh