{"repo":"joeavanzato/Trawler","free":true,"listed":false,"github":"https://github.com/joeavanzato/Trawler","clone":"git clone https://github.com/joeavanzato/Trawler.git","description":"PowerShell script helping Incident Responders discover potential adversary persistence mechanisms.","language":"PowerShell","stars":340,"topics":["dfir","powershell","blue-team","incident-response","malware","persistence","windows"],"license":"MIT","category":"cli-tools","readme_excerpt":"Dredging Windows for Persistence What is it? Trawler is a PowerShell script designed to help Incident Responders discover potential indicators of compromise on Windows hosts, primarily focused on persistence mechanisms including Scheduled Tasks, Services, Registry Modifications, Startup Items, Binary Modifications and more. Currently, trawler can detect most of the persistence techniques specifically called out by MITRE and Atomic Red Team with more detections being added on a regular basis. Main Features Scanning Windows OS for a variety of persistence techniques (Listed below) CSV Output with MITRE Technique and Investigation Jumpstart Metadata Analysis and Remediation Guidance Documentation (https://github.com/joeavanzato/Trawler/wiki/Analysis-and-Remediation-Guidance) Dynamic Risk Assignment for each detection Built-in Allow Lists for common Windows configurations spanning Windows 10/Server 2012 2016 2019 2022 to reduce noise Capture persistence metadata from 'golden' enterprise image (snapshot) for use as a dynamic allow-list at runtime Analyze mounted disk images via drive re-targeting How do I use it? Just download and run trawler.ps1 from an Administrative PowerShell/cmd prompt - any detections will be displayed in the console as well as written to a CSV ('detections.csv') in the current working directory. The generated CSV will contain Detection Name, Source, Risk, Metadata and the relevant MITRE Technique. Or use this one-liner from an Administrative PowerShell term","default_branch":null,"files":null,"tree":[],"storefront":"/r/joeavanzato","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/joeavanzato/Trawler/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}