Built-in Plugins
DFIR-OGRE provides a collection of plug‑ins, each dedicated to parsing a specific class of Windows artefacts. The built‑in plug‑ins cover a lot of artefacts that appears in a typical DFIR-ORC archive.
Retrieving the plugins
Plugins can be retrieved by cloning the dfir-ogre-plugin-windows repository
# Choose a location where you keep all the sources
mkdir -p ~/dfir-ogre && cd ~/dfir-ogre
git clone https://github.com/ANSSI-FR/dfir-ogre-plugin-windows.gitThe plugins are located in dfir-ogre-plugin-windows/configuration folder
Plugin list
Shows Windows XP Search Assistant queries with category, recency order, user ownership, and registry timestamps.
Application Specific
Shows Windows Activities Cache application activity, operation times, status, payloads, and provenance.
Services and Applications
Shows Amcache driver names, paths, hashes, versions, vendors, sizes, compilation times, and registry metadata.
Services and Applications
Lists driver hashes, names, versions, vendors, sizes, and compilation metadata from Amcache XML reports.
Services and Applications
Shows Amcache executable file paths, hashes, sizes, versions, vendors, timestamps, programs, and registry metadata.
Services and Applications
Lists Internet Explorer add-on identifiers, names, types, and publishers from Amcache XML reports.
Services and Applications
Lists installed software, installation times, hashes, versions, vendors, and file metadata from Amcache XML reports.
Services and Applications
Shows Amcache installed programs with names, versions, publishers, install dates, paths, and MSI identifiers.
Services and Applications
Lists installed programs and executable hashes, paths, versions, vendors, and run evidence from AEINV_PREVIOUS.
Services and Applications
Lists installed programs and executable hashes, paths, versions, vendors, and run evidence from FullCompatReport.
Services and Applications
Lists installed programs and executable hashes, paths, versions, vendors, and run evidence from AEINV WER reports.
Services and Applications
Shows the Internet Explorer anti-phishing user file with registry path, timestamp, owner, and access controls.
Application Specific
Shows AppCompatCache executable paths, file modification times, cache flags, and registry metadata.
Services and Applications
Shows autorun entries, launch commands, registry locations, users, signatures, hashes, and enabled state.
Persistence
Shows machine-wide SOFTWARE-hive autorun locations, persistence types, values, timestamps, owners, and permissions.
Persistence
Shows SYSTEM-hive autorun locations, persistence types, values, timestamps, owners, and permissions.
Persistence
Shows per-user autorun locations, persistence types, values, timestamps, owners, and permissions.
Persistence
Shows files and folders excluded from VSS or backups with exclusion type, path, owner, and registry timestamp.
File System
Shows BAM and DAM executable execution evidence with user SIDs, run times, paths, and registry metadata.
Services and Applications
Shows machine-wide COM registrations with CLSIDs, descriptions, executables, redirects, and registry metadata.
Windows Artefacts
Shows per-user COM registrations with CLSIDs, descriptions, executables, redirects, and registry metadata.
Windows Artefacts
Shows Chrome downloads with source URLs, saved paths, timestamps, sizes, states, and danger indicators.
Browser Artefacts
Shows Chrome extension identity, version, source, permissions, scripts, resources, and security policy.
Browser Artefacts
Shows Chrome URL visits with titles, timestamps, visit counts, referrers, and hidden status.
Browser Artefacts
Shows legacy Windows EVT events with provider, ID, message data, user, host, timestamps, and recovery status.
Logs
Shows Explorer search queries in recency order with value indexes, user ownership, and registry timestamps.
Application Specific
Shows FastFind filesystem matches with paths, NTFS identifiers, timestamps, attributes, hashes, and match context.
Fast Find
Shows FastFind Windows object matches with object type, name, path, and match description.
Fast Find
Shows FastFind registry matches with hive and key paths, values, data, timestamps, and snapshot context.
Fast Find
Shows Firefox downloads with source URLs, saved paths, timestamps, sizes, and deletion state.
Browser Artefacts
Shows Firefox add-on identity, version, source, permissions, origins, and installation or update times.
Browser Artefacts
Shows Firefox URL visits with titles, timestamps, visit counts, referrers, and hidden status.
Browser Artefacts
Shows files collected by ORC GetThis with paths, NTFS identifiers, sizes, hashes, timestamps, and match reasons.
File System
Shows raw Windows Registry keys and values with modification times, data types, owners, and access controls.
Windows Artefacts
Shows NTFS directory-index entries with paths, record identifiers, timestamps, sizes, attributes, and carving status.
File System
Shows Internet Explorer WebCache visits with URLs, cached files, timestamps, access counts, headers, and redirects.
Browser Artefacts
Shows Java cache downloads with URLs, server IPs, sizes, timestamps, completion state, and signing status.
Application Specific
Shows DLLs loaded by running processes with process IDs, command lines, module paths, base addresses, and sizes.
Services and Applications
Shows Windows shortcut and Jump List targets, arguments, timestamps, volume data, link flags, and extra metadata.
Windows Artefacts
Shows connected mass-storage devices with USB identifiers, serials, volume names, drive letters, users, and timestamps.
File System
Provides the complete text of a multiline artefact as one normalized record for downstream analysis.
File System
Shows per-user MUI cache executable paths and display descriptions with registry ownership and timestamps.
Services and Applications
Shows Windows IP, mask, gateway, DHCP, DNS, interface, registry ownership, and configuration timestamps.
System Information
Shows MFT file records with paths, NTFS identifiers, timestamps, attributes, hashes, and executable metadata.
File System
Shows Windows object-manager entries with types, namespace paths, symbolic-link targets, and creation times.
Windows Artefacts
Shows Program Compatibility Assistant application launches with executable paths and precise timestamps.
Logs
Shows Program Compatibility Assistant execution records with paths, times, status, vendor, version, and exit code.
Logs
Shows file rename or deletion operations queued for reboot with source and target paths plus registry metadata.
File System
Shows Windows Prefetch execution evidence with executable names, run counts, last-run times, loaded files, and volumes.
Services and Applications
Shows ORC process records with names, paths, command lines, IDs, parent IDs, sessions, and timestamps.
Services and Applications
Shows ORC process records with identity, ancestry, command lines, users, timestamps, resource use, and status.
Services and Applications
Shows Windows RecentApps launch counts and access times plus recently used file paths and arguments.
Services and Applications
Shows Recycle Bin entries with original paths, deletion times, sizes, and format headers.
File System
Shows commands entered in the Windows Run dialog with MRU order, user ownership, and registry timestamps.
Services and Applications
Shows scheduled-task identity, triggers, actions, commands, arguments, authorship, timing, and registry security.
Persistence
Shows Windows service names, start modes, executable paths, accounts, dependencies, parameters, and registry metadata.
Persistence
Shows folders browsed in Explorer with reconstructed paths, item metadata, timestamps, users, and registry provenance.
File System
Shows installed application-compatibility shim databases with GUIDs, target paths, install times, and registry metadata.
Services and Applications
Shows per-application focus, input, audio, network, and duration statistics recorded by Windows SRUM.
Services and Applications
Shows per-application CPU, I/O, foreground, and background resource usage over time from Windows SRUM.
Services and Applications
Preserves opaque per-application SRUM energy-estimation records with application, user, and timestamp context.
Services and Applications
Shows SRUM battery energy events with state transitions, capacity, charge level, cycle count, and timestamps.
Windows Artefacts
Shows long-term SRUM energy estimates by application, user, power source, activity state, and capacity.
Windows Artefacts
Shows SRUM network connection sessions with application, user, interface, profile, start time, and duration.
Network
Shows per-application SRUM network traffic with users, interfaces, profiles, timestamps, and byte counts.
Network
Shows Windows Server SRUM processor time with application, user, and timestamp context.
Services and Applications
Shows Windows Server SRUM inbound, outbound, and total network bytes by application, user, and time.
Network
Shows Windows Server SRUM physical-disk sizes with application, user, and timestamp context.
File System
Shows Windows Server SRUM storage-volume capacity and usage with application, user, and timestamp context.
File System
Shows SRUM tagged-energy records with application, user, and timestamp identifiers for correlation.
Windows Artefacts
Shows SRUM VFU provider records with application, user, and timestamp identifiers for correlation.
Windows Artefacts
Shows SRUM push-notification activity with application, user, notification type, payload size, and network type.
Windows Artefacts
Shows Subject Interface Packages with GUIDs, names, DLL paths, entry points, owners, and registry timestamps.
Services and Applications
Shows Windows host identity, OS version, build, install and shutdown times, role, architecture, and timezone.
System Information
Shows Windows host, OS, installation, boot, hardware, BIOS, processor, network, and update information.
System Information
Shows captured Windows TCP and UDP endpoints with owning processes, connection state, and local or remote addresses.
Network
Shows per-user program execution counts, focus metrics, launch types, last-run times, and registry provenance.
Services and Applications
Shows Windows user profiles with SIDs, paths, hidden or admin status, state, timestamps, and registry permissions.
System Information
Shows USN Journal file changes with paths, NTFS identifiers, timestamps, reasons, attributes, and source snapshots.
File System
Shows Windows volumes with identifiers, mount points, types, locations, shadow-copy IDs, and collected artefact sets.
File System
Shows Volume Shadow Copy snapshots with snapshot IDs, source volumes, device paths, creation times, and attributes.
File System
Shows Windows Error Reporting events with application, crash or hang metadata, timestamps, status, and report IDs.
Logs
Shows Windows EVTX events with timestamps, providers, event IDs, users, hosts, processes, and event data.
Logs
Shows per-user X.509 certificates with subjects, issuers, validity, keys, fingerprints, and registry provenance.
System Information
Shows machine-wide X.509 certificates with subjects, issuers, validity, keys, fingerprints, and registry provenance.
System Information