Skip to content

Commit

Permalink
Add Anti Virus paths
Browse files Browse the repository at this point in the history
  • Loading branch information
Zawadidone committed Aug 8, 2023
1 parent 8d15a39 commit 6276633
Showing 1 changed file with 10 additions and 0 deletions.
10 changes: 10 additions & 0 deletions acquire/acquire.py
Original file line number Diff line number Diff line change
Expand Up @@ -875,6 +875,8 @@ class AV(Module):
("file", "sysvol/ProgramData/Avast Software/Avast/Chest/index.xml"),
# Avira
("dir", "sysvol/ProgramData/Avira/Antivirus/LOGFILES"),
("dir", "sysvol/ProgramData/Avira/Security/Logs"),
("dir", "sysvol/ProgramData/Avira/VPN"),
# Bitdefender
("dir", "sysvol/ProgramData/Bitdefender/Endpoint Security/Logs"),
("dir", "sysvol/ProgramData/Bitdefender/Desktop/Profiles/Logs"),
Expand All @@ -885,9 +887,16 @@ class AV(Module):
("dir", "sysvol/ProgramData/crs1/Logs"),
("dir", "sysvol/ProgramData/apv2/Logs"),
("dir", "sysvol/ProgramData/crb1/Logs"),
# Cylance
("dir", "sysvol/ProgramData/Cylance/Desktop"),
("dir", "sysvol/ProgramData/Cylance/Optics/Log"),
("dir", "sysvol/Program Files/Cylance/Desktop/log"),
# ESET
("dir", "sysvol/Documents and Settings/All Users/Application Data/ESET/ESET NOD32 Antivirus/Logs"),
("dir", "sysvol/ProgramData/ESET/ESET NOD32 Antivirus/Logs"),
("dir", "sysvol/ProgramData/ESET/ESET Security/Logs"),
("dir", "sysvol/ProgramData/ESET/RemoteAdministrator/Agent/EraAgentApplicationData/Logs"),
("dir", "sysvol/Windows/System32/config/systemprofile/AppData/Local/ESET/ESET Security/Quarantine"),
# Emsisoft
("glob", "sysvol/ProgramData/Emsisoft/Reports/scan*.txt"),
# F-Secure
Expand Down Expand Up @@ -949,6 +958,7 @@ class AV(Module):
("dir", "sysvol/ProgramData/Microsoft/Microsoft AntiMalware/Support"),
("glob", "sysvol/Windows/System32/winevt/Logs/Microsoft-Windows-Windows Defender*.evtx"),
("dir", "sysvol/ProgramData/Microsoft/Windows Defender/Support"),
("dir", "sysvol/ProgramData/Microsoft/Windows Defender/Scans/History/Service/DetectionHistory"),
("file", "sysvol/Windows/Temp/MpCmdRun.log"),
("file", "sysvol/Windows.old/Windows/Temp/MpCmdRun.log"),
]
Expand Down

0 comments on commit 6276633

Please sign in to comment.