SrumECmd
How to use SrumECmd to parse the Windows SRUM database in order to provide evidence of program execution and network connections during incident investigations.
Tool Name
Version
MITRE ATT&CK Tactic
MITRE ATT&CK Technique
Instructions
Parsing a Live or Copied SRUM.dat Database
SrumECmd.exe -f C:\Windows\System32\sru\SRUDB.dat --csv /path/to/outputOutput





Last updated