-
Notifications
You must be signed in to change notification settings - Fork 104
New issue
Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? # to your account
Wrong informations on remote collection #2
Comments
Yeah, that's correct. You will get process and system data, but the user Thanks!
|
Any progress so far? |
Unfortunately I haven't had much time to dig into this one yet. Hope to have a resolution soon. |
Hi, Yeah I feel the same pain as target user is not other than the user script is currently running under. One way I could think of is to get the list of all active users and loop each user to collect user's data. Any thoughts? Also some of the extracted output is not parsed into the the main html file (such as Downloads, installed softwares etc). On a separate note note the script is still useful and I appreciate your efforts in this regards. |
if you collect the informations from a remote system, most of the data is useless because the script is reading informations from the current security context which is of course my own remote login and not the user currently logged on the infected computer. To do a good and full investigation it would be important to get informations about the user who triggered the infection...
any solution for that?
The text was updated successfully, but these errors were encountered: