Skip to main content

IR tool for aquiring memory images from windows EC2 instances on AWS

Project description

Espresso IR

Introduction

Espresso IR provides the fuctionality to automate memory aquisitions of Windows based EC2 instances and stores them in an S3 bucket. Currently it uses DumpIt to facilitate the memory aquisition part but with some minor edits you could use your tool of choice.

Getting Started

use pip install espresso_ir to install the module.

GitHub repositiory https://github.com/Terrizmo/espresso_ir

Requirements

You must have an account with programatic access to your AWS environment. Once you have the access-key-id and secret-access-key. Use aws configure to store these in your home directory. These details will then be used each time your run an espresso_ir command.

This tool has been designed to use DumpIt by comae. Other memory acquisition tools may be availible in the future.

Finally System manager must be able to communicate with the system manager agent on the EC2 instances you wish to acquire the memory from. You can create the necessary role with the required policies with this tool, --setup flag. Note if you add this role after the the system manager agent has turned on you will need to reboot the agent or the instance to get this functionality. Rebooting the EC2 instance will lose artifacts in memory, proabably all of them!

Include essential instructions for:

  • Installing It
  • Configuring It
  • Running it

TODO

  • Next steps
  • Features planned
  • Known bugs (shortlist)

Contact

  • Email address
  • Google Group/mailing list (if applicable)
  • IRC or Slack (if applicable)

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

espresso_ir-0.0.1.tar.gz (11.6 kB view hashes)

Uploaded Source

Built Distribution

espresso_ir-0.0.1-py3-none-any.whl (16.5 kB view hashes)

Uploaded Python 3

Supported by

AWS AWS Cloud computing and Security Sponsor Datadog Datadog Monitoring Fastly Fastly CDN Google Google Download Analytics Microsoft Microsoft PSF Sponsor Pingdom Pingdom Monitoring Sentry Sentry Error logging StatusPage StatusPage Status page