Skip to content

Built-in Plugins

DFIR-OGRE provides a collection of plug‑ins, each dedicated to parsing a specific class of Windows artefacts. The built‑in plug‑ins cover a lot of artefacts that appears in a typical DFIR-ORC archive.

Retrieving the plugins

Plugins can be retrieved by cloning the dfir-ogre-plugin-windows repository

# Choose a location where you keep all the sources
mkdir -p ~/dfir-ogre && cd ~/dfir-ogre

git clone https://github.com/ANSSI-FR/dfir-ogre-plugin-windows.git

The plugins are located in dfir-ogre-plugin-windows/configuration folder


Plugin list

Acmru
Shows Windows XP Search Assistant queries with category, recency order, user ownership, and registry timestamps.
Application Specific
Activity Cache
Shows Windows Activities Cache application activity, operation times, status, payloads, and provenance.
Services and Applications
Amcache Driver
Shows Amcache driver names, paths, hashes, versions, vendors, sizes, compilation times, and registry metadata.
Services and Applications
Amcache Driver Xml
Lists driver hashes, names, versions, vendors, sizes, and compilation metadata from Amcache XML reports.
Services and Applications
Amcache Files
Shows Amcache executable file paths, hashes, sizes, versions, vendors, timestamps, programs, and registry metadata.
Services and Applications
Amcache Ie Addon Xml
Lists Internet Explorer add-on identifiers, names, types, and publishers from Amcache XML reports.
Services and Applications
Amcache Installer Xml
Lists installed software, installation times, hashes, versions, vendors, and file metadata from Amcache XML reports.
Services and Applications
Amcache Program
Shows Amcache installed programs with names, versions, publishers, install dates, paths, and MSI identifiers.
Services and Applications
Amcache Program Previous
Lists installed programs and executable hashes, paths, versions, vendors, and run evidence from AEINV_PREVIOUS.
Services and Applications
Amcache Program Report
Lists installed programs and executable hashes, paths, versions, vendors, and run evidence from FullCompatReport.
Services and Applications
Amcache Program Wer
Lists installed programs and executable hashes, paths, versions, vendors, and run evidence from AEINV WER reports.
Services and Applications
Antifishing File
Shows the Internet Explorer anti-phishing user file with registry path, timestamp, owner, and access controls.
Application Specific
App Compat Cache
Shows AppCompatCache executable paths, file modification times, cache flags, and registry metadata.
Services and Applications
Autoruns
Shows autorun entries, launch commands, registry locations, users, signatures, hashes, and enabled state.
Persistence
Autoruns Reg Software
Shows machine-wide SOFTWARE-hive autorun locations, persistence types, values, timestamps, owners, and permissions.
Persistence
Autoruns Reg System
Shows SYSTEM-hive autorun locations, persistence types, values, timestamps, owners, and permissions.
Persistence
Autoruns Reg User
Shows per-user autorun locations, persistence types, values, timestamps, owners, and permissions.
Persistence
Backup Exclude
Shows files and folders excluded from VSS or backups with exclusion type, path, owner, and registry timestamp.
File System
Bam Dam
Shows BAM and DAM executable execution evidence with user SIDs, run times, paths, and registry metadata.
Services and Applications
CLSID Software
Shows machine-wide COM registrations with CLSIDs, descriptions, executables, redirects, and registry metadata.
Windows Artefacts
CLSID Users
Shows per-user COM registrations with CLSIDs, descriptions, executables, redirects, and registry metadata.
Windows Artefacts
Chrome Download History
Shows Chrome downloads with source URLs, saved paths, timestamps, sizes, states, and danger indicators.
Browser Artefacts
Chrome Extension
Shows Chrome extension identity, version, source, permissions, scripts, resources, and security policy.
Browser Artefacts
Chrome History
Shows Chrome URL visits with titles, timestamps, visit counts, referrers, and hidden status.
Browser Artefacts
Evt
Shows legacy Windows EVT events with provider, ID, message data, user, host, timestamps, and recovery status.
Logs
Explorer Search History
Shows Explorer search queries in recency order with value indexes, user ownership, and registry timestamps.
Application Specific
Fastfind File
Shows FastFind filesystem matches with paths, NTFS identifiers, timestamps, attributes, hashes, and match context.
Fast Find
Fastfind Object
Shows FastFind Windows object matches with object type, name, path, and match description.
Fast Find
Fastfind Registry
Shows FastFind registry matches with hive and key paths, values, data, timestamps, and snapshot context.
Fast Find
Firefox Download History
Shows Firefox downloads with source URLs, saved paths, timestamps, sizes, and deletion state.
Browser Artefacts
Firefox Extension
Shows Firefox add-on identity, version, source, permissions, origins, and installation or update times.
Browser Artefacts
Firefox History
Shows Firefox URL visits with titles, timestamps, visit counts, referrers, and hidden status.
Browser Artefacts
Getthis
Shows files collected by ORC GetThis with paths, NTFS identifiers, sizes, hashes, timestamps, and match reasons.
File System
Hive
Shows raw Windows Registry keys and values with modification times, data types, owners, and access controls.
Windows Artefacts
I30 info
Shows NTFS directory-index entries with paths, record identifiers, timestamps, sizes, attributes, and carving status.
File System
Ie Webcache History
Shows Internet Explorer WebCache visits with URLs, cached files, timestamps, access counts, headers, and redirects.
Browser Artefacts
Java Idx
Shows Java cache downloads with URLs, server IPs, sizes, timestamps, completion state, and signing status.
Application Specific
List Dlls
Shows DLLs loaded by running processes with process IDs, command lines, module paths, base addresses, and sizes.
Services and Applications
Lnk
Shows Windows shortcut and Jump List targets, arguments, timestamps, volume data, link flags, and extra metadata.
Windows Artefacts
Mass Storage
Shows connected mass-storage devices with USB identifiers, serials, volume names, drive letters, users, and timestamps.
File System
Merge File
Provides the complete text of a multiline artefact as one normalized record for downstream analysis.
File System
Mui Cache
Shows per-user MUI cache executable paths and display descriptions with registry ownership and timestamps.
Services and Applications
Network Configuration
Shows Windows IP, mask, gateway, DHCP, DNS, interface, registry ownership, and configuration timestamps.
System Information
Ntfs Info
Shows MFT file records with paths, NTFS identifiers, timestamps, attributes, hashes, and executable metadata.
File System
Object Info
Shows Windows object-manager entries with types, namespace paths, symbolic-link targets, and creation times.
Windows Artefacts
Pca App Launch
Shows Program Compatibility Assistant application launches with executable paths and precise timestamps.
Logs
Pca General Record
Shows Program Compatibility Assistant execution records with paths, times, status, vendor, version, and exit code.
Logs
Pending Rename
Shows file rename or deletion operations queued for reboot with source and target paths plus registry metadata.
File System
Prefetch
Shows Windows Prefetch execution evidence with executable names, run counts, last-run times, loaded files, and volumes.
Services and Applications
Processes Orc V1
Shows ORC process records with names, paths, command lines, IDs, parent IDs, sessions, and timestamps.
Services and Applications
Processes Orc V2
Shows ORC process records with identity, ancestry, command lines, users, timestamps, resource use, and status.
Services and Applications
Recent App
Shows Windows RecentApps launch counts and access times plus recently used file paths and arguments.
Services and Applications
Recycle Bin
Shows Recycle Bin entries with original paths, deletion times, sizes, and format headers.
File System
Run Mru
Shows commands entered in the Windows Run dialog with MRU order, user ownership, and registry timestamps.
Services and Applications
Scheduled Tasks
Shows scheduled-task identity, triggers, actions, commands, arguments, authorship, timing, and registry security.
Persistence
Services Control Set
Shows Windows service names, start modes, executable paths, accounts, dependencies, parameters, and registry metadata.
Persistence
Shellbags
Shows folders browsed in Explorer with reconstructed paths, item metadata, timestamps, users, and registry provenance.
File System
Shim Database
Shows installed application-compatibility shim databases with GUIDs, target paths, install times, and registry metadata.
Services and Applications
Srum App Timeline
Shows per-application focus, input, audio, network, and duration statistics recorded by Windows SRUM.
Services and Applications
Srum Application Resources
Shows per-application CPU, I/O, foreground, and background resource usage over time from Windows SRUM.
Services and Applications
Srum Energy Estimation
Preserves opaque per-application SRUM energy-estimation records with application, user, and timestamp context.
Services and Applications
Srum Energy Usage
Shows SRUM battery energy events with state transitions, capacity, charge level, cycle count, and timestamps.
Windows Artefacts
Srum Energy Usage Long Term
Shows long-term SRUM energy estimates by application, user, power source, activity state, and capacity.
Windows Artefacts
Srum Network Connectivity Usage
Shows SRUM network connection sessions with application, user, interface, profile, start time, and duration.
Network
Srum Network Data Usage
Shows per-application SRUM network traffic with users, interfaces, profiles, timestamps, and byte counts.
Network
Srum Sdp Cpu
Shows Windows Server SRUM processor time with application, user, and timestamp context.
Services and Applications
Srum Sdp Network
Shows Windows Server SRUM inbound, outbound, and total network bytes by application, user, and time.
Network
Srum Sdp Physical Disk
Shows Windows Server SRUM physical-disk sizes with application, user, and timestamp context.
File System
Srum Sdp Volume
Shows Windows Server SRUM storage-volume capacity and usage with application, user, and timestamp context.
File System
Srum Tagged Energy
Shows SRUM tagged-energy records with application, user, and timestamp identifiers for correlation.
Windows Artefacts
Srum Vfuprov
Shows SRUM VFU provider records with application, user, and timestamp identifiers for correlation.
Windows Artefacts
Srum Wpn Provider
Shows SRUM push-notification activity with application, user, notification type, payload size, and network type.
Windows Artefacts
Subject Interface Package
Shows Subject Interface Packages with GUIDs, names, DLL paths, entry points, owners, and registry timestamps.
Services and Applications
System Info Reg
Shows Windows host identity, OS version, build, install and shutdown times, role, architecture, and timezone.
System Information
Systeminfo
Shows Windows host, OS, installation, boot, hardware, BIOS, processor, network, and update information.
System Information
Tcp Connections
Shows captured Windows TCP and UDP endpoints with owning processes, connection state, and local or remote addresses.
Network
User Assist
Shows per-user program execution counts, focus metrics, launch types, last-run times, and registry provenance.
Services and Applications
User Profile
Shows Windows user profiles with SIDs, paths, hidden or admin status, state, timestamps, and registry permissions.
System Information
Usn Info
Shows USN Journal file changes with paths, NTFS identifiers, timestamps, reasons, attributes, and source snapshots.
File System
Volstats
Shows Windows volumes with identifiers, mount points, types, locations, shadow-copy IDs, and collected artefact sets.
File System
Vss Snapshot
Shows Volume Shadow Copy snapshots with snapshot IDs, source volumes, device paths, creation times, and attributes.
File System
Wer Reports
Shows Windows Error Reporting events with application, crash or hang metadata, timestamps, status, and report IDs.
Logs
Windows Events
Shows Windows EVTX events with timestamps, providers, event IDs, users, hosts, processes, and event data.
Logs
X509 Certificates Users
Shows per-user X.509 certificates with subjects, issuers, validity, keys, fingerprints, and registry provenance.
System Information
X509Cert Software
Shows machine-wide X.509 certificates with subjects, issuers, validity, keys, fingerprints, and registry provenance.
System Information