DFIR ORC Local Configuration File¶
DFIR ORC can be locally configured to specify a limited set of configuration elements. Typically, those elements are the client’s specific configuration options (like the upload method, priority, temporary folder, etc.). The local configuration can be specified using:
The
/local=<LocalConfigFile>command-line optionA file in the same directory as DFIR ORC, with the same base name and .xml extension, e.g.:
<SomeDirectory>\\DFIR-Orc.exe
<SomeDirectory>\\DFIR-Orc.xml
The index of this sections consists in the following XML skeleton file, which features all the elements that can appear in a real configuration file. It is not a usable configuration, in the sense that it does not contain any attribute key or value, and can exhibit incompatible elements. Its point is to be exhaustive from the point of view of existing usable elements.
dfir-orc Element¶
optional=no, default=N/A
Root element
Attributes¶
- priority (optional=yes, default=normal)
Configures Windows process (and thread) priority class. Available values for this attribute are: Low, Normal & High.
- powerstate (optional=yes, default=unmodified power state)
Configures DFIR ORC’s main thread power state to optionally prevent the system from going to sleep when DFIR ORC is running. Allowed value is a comma separated list of
SystemRequired
Displayrequired
UserPresent
AwayMode.
When only looking to prevent sleep, recommended value for this option is SystemRequired,AwayMode. More information on power states: https://docs.microsoft.com/en-us/windows/desktop/api/winbase/nf-winbase-setthreadexecutionstate
temporary Element¶
optional=yes, default=%temp%, parent element: dfir-orc
This element configures the location of temporary files created by the tool. The inner text of this element contains the name of the folder. Environment variables will be substituted.
Attributes¶
None
Example¶
<temporary>%Temp%\WorkingTemp</temporary>
output Element¶
optional=no, default=’.’, parent element: dfir-orc
This element configures the folder where the various archives will be created. A local drive or a remote SMB share can be specified (in the latter, the upload syntax should be privileged to reduce network congestion). Environment variables will be substituted.
Attributes¶
None
Example¶
<output>%Temp%</output>
upload Element¶
optional=yes, default=no upload, parent element: dfir-orc
The upload element is used to configure an optional upload operation when an archive is created.
Attributes¶
- job (optional=yes, default=none)
Describes the upload operation.
- method (optional=no, default=N/A)
Describes the method to upload the files: “filecopy” (uses SMB), “BITS”, or “rest” (HTTP/HTTPS, see REST upload).
- server (optional=no, default=N/A)
Specifies the server name (e.g. file://servername or http://servername, or https://servername) when using BITS or SMB.
For “rest”, a scheme and a host, optionally with a port, e.g.
https://servername:8443. The path is given in the rest element.
- uri (optional=yes, default=N/A)
The destination as a single URL, e.g.
https://user:password@servername/upload, instead ofserver,path,userandpassword.
- path (optional=no, default= / or \ depending on the method)
Specifies the file share or folder for the upload
- user (optional=yes, default=the current user (executing DFIR ORC))
Specifies the user name to be used to connect to the remote server.
- password (optional=yes, default=N/A)
Specifies the password to use (for the user defined above)
- authscheme (optional=yes, default=Negotiate (if a user name is specified, anonymous otherwise))
Specifies the authentication scheme for the connection. Possible scheme values are:
Anonymous
Basic
NTLM
Kerberos
Negotiate
AWSv4 (
method="rest"only, see AWS SigV4)
- operation (optional=yes, default=copy)
“copy” or “move” the archives to the upload server. With “move”, the local file is deleted once it has been sent.
- retry (optional=yes, default=0)
Number of extra attempts at this entry before trying the next one:
retry="2"means three attempts. At most 10. Retries take place at the end of the collection. No effect withmode="async".
- retry_delay (optional=yes, default=30)
Seconds between two attempts. At most 1800, and
retryxretry_delaymay not exceed 1800 seconds.
- mode (optional=yes, default=sync)
“sync” or “async”: upload can be synchronous or asynchronous (asynchronous allows DFIR ORC to exit prior to BITS jobs completes). “async” is not supported for “filecopy” method.
- include (optional=yes, default=none)
Specifies a comma (or semicolon) separated list of patterns, matching the file name of archives, that determine whether an output archive from
DFIR-Orc.exewill be uploaded to the specified location. When missing, all archives are uploaded (if not explicitly excluded, see below). When specified, only archives whose name matches one of the patterns will be uploaded.
- exclude (optional=yes, default=none)
Specifies a comma (or semicolon) separated list of patterns, matching the file name of archives, that determine whether an output archive should not be uploaded. When excluded, an output archive is left intact in the output directory (i.e. regardless of the
operationattribute). Theexcludeattribute takes precedence over theincludeattribute, meaning an archive whose name matches bothincludeandexcludepatterns will be excluded.
- delete_smb_share (optional=yes, default=none)
Currently only available for BITS over SMB. When set to “true” the connection to the share will be deleted at the end of jobs (with the use of net use /del). This option should only be needed when the share is served by Samba.
include and exclude select collected data: the archives produced by the commands. The run’s own files - the log, the console output, the outline and the outcome - are not affected by these filters.
Several upload elements may be declared. They form a fallback list, tried in order until one succeeds, and each entry is used with its own operation and its own include/exclude: a fallback that says operation="copy" keeps the local archive even when the first entry asked to move it, and one that excludes a file does not receive it.
The filters are per destination, in both directions: a file the first entry excludes is still offered to a later entry that accepts it. exclude says “this destination does not take that archive”, not “this archive stays on the machine” - to keep a file from leaving at all, it must be excluded from every entry.
An entry that cannot be configured is skipped, as long as another entry remains usable.
The upload entries of a local configuration are added after those of the embedded configuration, as further fallbacks. Before DFIR ORC 10.4.0, they replaced them.
Example¶
<upload job="DFIR-ORC" method="BITS"
server="http://MyBits.MyOrg.com"
path="upload"
user="MyORG\BITSUploadClient" password="P@ssw0rd!"
operation="move"
include="DFIR-ORC_*_Hives.7z" />
REST upload¶
With method="rest" the archives are uploaded over HTTP or HTTPS. The requests are described by rest child elements: a single PUT, or the dialog of a server such as WebDAV, Nextcloud or S3 (see REST server dialogs).
Warning
The REST method is new and has only been tested in a laboratory. Before relying on it, run a complete collection against your own server.
The following attributes apply to this method only.
Transport security
- https_security (optional=yes, default=”tls1.3, tls1.2[xp]”)
Minimum TLS version, as a comma separated list of “tls1.0” to “tls1.3”: the version given and every higher one are allowed. A version followed by “[xp]” or “[seven]” applies to that system only. “os-default” keeps the system settings, still requiring TLS 1.2 or higher; “os-max” uses only the highest version the system supports.
The default requires TLS 1.3, or TLS 1.2 on Windows XP and 2003.
- server_cert_pin (optional=yes, default=none)
One or more certificates, PEM or base64, separated by commas. The server is accepted only if the public key of its certificate matches one of them. This is the way to use a self-signed server. Give several certificates to allow a key change.
- insecure (optional=yes, default=false)
Allows plain HTTP and TLS below 1.2, and disables certificate validation. For a laboratory only; prefer
server_cert_pin.
- follow_redirects (optional=yes, default=false)
Follows HTTP redirections. Off by default, since a redirection would send the credentials to another server.
Authentication
The scheme is given by authscheme:
Basic - with
userandpassword.NTLM, Kerberos, Negotiate - with
userandpassword. The account DFIR ORC runs under is never used.AWSv4 - see AWS SigV4.
A token, e.g. Bearer - written as a header, see below.
Use an account dedicated to uploads, that can be revoked: the credentials embedded in the collector can be read by whoever obtains it.
AWS SigV4¶
authscheme="AWSv4" signs each request as an S3 server expects: AWS S3, or a compatible server such as MinIO, RustFS or SeaweedFS.
Attribute |
Required |
Meaning |
|---|---|---|
|
yes |
the access key |
|
yes |
the secret key |
|
no |
the session token of a temporary credential |
|
yes |
the region, e.g. |
|
no (default |
the service name |
|
no (default |
|
The keys are used as written: environment variables are not expanded in them. A temporary credential, with
session_token, avoids embedding a permanent secret.Write the
pathas plain text, e.g. a space as a space, not encoded as%20.Redirections are not followed.
Not available on Windows XP and 2003.
<upload job="DFIR-ORC" method="rest"
server="https://s3.mycorp.example"
operation="move"
authscheme="AWSv4"
access_key="AKIA..." secret_key="..." aws_region="eu-west-3">
<rest http_method="PUT" path="/orc-bucket/incoming/{upload.filename}" body="{upload.local_path}"/>
</upload>
Headers sent with every request
- http_header (optional=yes, default=none)
One header line, sent with every request, e.g.
http_header="Authorization: Bearer <token>".
To send several headers, use header child elements of upload, one line each:
<upload method="rest" server="https://collect.mycorp.example">
<header>Authorization: Bearer eyJhbGciOi...</header>
<header>X-Collection: nightly</header>
<rest http_method="PUT" path="/incoming/{upload.filename}" body="{upload.local_path}"/>
</upload>
A header inside a rest element is sent with that request only. Headers may use the placeholders below.
Proxy
- proxy (optional=yes, default=the machine proxy settings)
How the proxy is found:
Value
Meaning
(attribute absent)
the machine proxy settings (
netsh winhttp)""/direct/noneno proxy
systemthe machine proxy settings
wpad/autoautomatic discovery (WPAD)
pac:<url>or<url>.paca PAC script
host:portthis proxy
- proxy_bypass (optional=yes, default=none)
Hosts reached without the proxy, e.g.
<local>;*.corp.
- proxy_user, proxy_password (optional=yes, default=none)
Credentials for the proxy.
proxymust be set, e.g. to “system”. Use an account dedicated to the proxy.
- proxy_authscheme (optional=yes, default=Anonymous)
“Basic”, “NTLM” or “Negotiate”. For NTLM and Negotiate, give a domain user, e.g.
DOMAIN\user.
Placeholders
The path, http_query, body and offset attributes of a rest element, and its headers, may use these placeholders:
Placeholder |
Description |
|---|---|
{upload.filename} |
name of the file |
{upload.filename_base64} |
name of the file, base64 encoded |
{upload.local_path} |
local path of the file |
{upload.range_start} |
offset of the chunk being sent |
{upload.range_end} |
offset of the last byte of the chunk |
{upload.range_length} |
length of the chunk |
{upload.total_size} |
size of the file |
{upload.random:<charset>:<length>} |
a random string, the same for the whole file; charset is hex, num, alpha or alnum, length is 1 to 64 |
A value captured with a response element is written {name}.
REST example¶
Warning
Understand each parameter before using a configuration: a wrong setting can make the upload insecure, for instance by sending the collection in clear text or to another server.
<upload job="DFIR-ORC" method="rest"
server="https://collect.mycorp.example"
operation="move"
proxy="system" proxy_authscheme="NTLM" proxy_user="MYCORP\orc-proxy" proxy_password="P@ssw0rd!"
server_cert_pin="MIIDLDCCAhSgAwIBAgIU...">
<rest http_method="PUT" path="/incoming/{upload.filename}" body="{upload.local_path}"
chunk_size="1048576">
<header>Content-Range: bytes {upload.range_start}-{upload.range_end}/{upload.total_size}</header>
</rest>
</upload>
A resumable upload asks the server what it already holds, then starts from there:
<upload method="rest" server="https://collect.mycorp.example" operation="move">
<rest http_method="HEAD" path="/incoming/{upload.filename}" accept_status="404">
<response header="content-length" name="remote_size" default="0"/>
</rest>
<rest http_method="PUT" path="/incoming/{upload.filename}" body="{upload.local_path}"
offset="{remote_size}" chunk_size="1048576">
<header>Content-Range: bytes {upload.range_start}-{upload.range_end}/{upload.total_size}</header>
</rest>
</upload>
More examples, for each tested server, are in the tests/RestAgent directory of the source tree.
rest Element¶
optional=yes, default=N/A, parent element: upload
Describes one request sent by method="rest". Requests are sent in the order they are declared; one of them sends the file.
Attributes¶
- http_method (optional=no, default=N/A)
The HTTP verb, e.g. “PUT”, “POST”, “PATCH”, “HEAD”, “MKCOL”, “MOVE”.
- path (optional=no, default=N/A)
Path of the request on the server, as a template.
- http_query (optional=yes, default=none)
Query string appended to the path, as a template, e.g.
?start={upload.range_start}.
- body (optional=yes, default=no body)
The file to send, normally
{upload.local_path}.
- offset (optional=yes, default=0)
Where to start in the file, e.g.
{remote_size}captured by a previous step, to resume an upload.
- chunk_size (optional=yes, default=the whole file in one request)
Sends the file in chunks of that many bytes. Required beyond 4 GB. Each chunk must be identified by
{upload.range_start}in the path, the query or a header.
- accept_status (optional=yes, default=any 2xx)
Additional HTTP status codes to treat as success, comma separated, e.g.
404on a probe that legitimately finds nothing.
- session (optional=yes, default=once per file)
session="once"runs the step only once, before the first file, instead of once per file: for a login. Cookies set by the server are kept for the following steps.
header child element¶
One header line, sent with this request only. Repeat the element for several headers.
response child element¶
Captures a value from the server’s answer to this step, for later steps to use. Each response reads exactly one of header, form_input, attribute or dav_property.
- name (optional=no, default=N/A)
Name of the captured value, written
{name}in a later step. It cannot start withupload..
- header (optional=yes, default=none)
Name of the response header to capture.
- form_input (optional=yes, default=none)
Name of an HTML
<input>- typically a hidden token - whose value is read from the returned page.
- attribute (optional=yes, default=none)
Name of an HTML attribute whose value is read from the returned page, e.g.
data-requesttoken.If
form_inputorattributefinds nothing and nodefaultis given, the upload stops.
- dav_property (optional=yes, default=none)
Name of a WebDAV property read from a PROPFIND answer, e.g.
getcontentlength. Not available in the standard build.
- default (optional=yes, default=empty)
Value used when the server does not return the header, property, input or attribute.
form child element¶
One field of a form sent as the request body, e.g. the password of a login form. Repeat the element for several fields.
- field (optional=no, default=N/A)
Name of the field.
- value (optional=no, default=N/A)
Value of the field. It may use a value captured by an earlier step, e.g.
{rt}.
The step must use POST, PUT or PATCH, and cannot also carry body.
<upload method="rest" server="https://share.mycorp.example" operation="copy">
<rest http_method="GET" path="/s/SHARETOKEN" session="once">
<response form_input="requesttoken" name="rt"/>
</rest>
<rest http_method="POST" path="/s/SHARETOKEN" session="once" accept_status="302,303">
<form field="password" value="a-scoped-share-password"/>
<form field="requestToken" value="{rt}"/>
</rest>
<rest http_method="PUT" path="/public.php/dav/files/SHARETOKEN/{upload.filename}"
body="{upload.local_path}"/>
</upload>
The two login steps run once; the files are then sent with the session they opened. See REST configuration examples for the form login of Nextcloud.
REST server dialogs¶
The rest elements describe requests, not a protocol: another server can be used by writing its own sequence of requests. These dialogs have been tested:
Dialog |
Steps |
Where it has been exercised |
|---|---|---|
Single |
one body step |
the reference sink, Nextcloud 35, MinIO, RustFS, SeaweedFS |
Chunked |
one body step with |
the reference sink |
Resume |
a |
the reference sink |
WebDAV |
|
the reference sink, Nextcloud 35 |
Nextcloud chunked upload v2 |
|
Nextcloud 35 |
S3 |
one |
MinIO, RustFS, SeaweedFS |
A
PUTreplaces the file: resuming only works with a server that appends. With Nextcloud or S3, an interrupted upload starts again from the beginning.Chunks are named by their offset, and the server must sort them as numbers. Nextcloud 35 does.
With S3, a file is sent in a single request, which limits it to 5 GB.
The test configurations for these servers are in tests/RestAgent of the source tree.
REST configuration examples¶
Warning
These examples show the syntax. They are not equally secure: each one says what it protects and what it does not. Do not reuse one without understanding it.
The collector may run on a compromised host: its configuration, credentials included, can be read.
Question |
Stronger |
Weaker |
|---|---|---|
Is the server authenticated? |
|
|
What can the embedded credential do? |
only write, revocable, short-lived |
anonymous write; read or delete rights |
Is the collection encrypted? |
a recipient is configured |
no recipient |
Configure a recipient with every example below.
HTTPS with a pinned certificate and a scoped account (WebDAV, Nextcloud)¶
<upload method="rest" server="https://collect.mycorp.example" operation="copy"
authscheme="Basic" user="orc-upload" password="..."
https_security="tls1.3, tls1.2"
server_cert_pin="MIIDJTCCAg2gAwIBAgIU...">
<rest http_method="MKCOL" path="/remote.php/dav/files/orc-upload/incoming/" accept_status="405"/>
<rest http_method="PUT" path="/remote.php/dav/files/orc-upload/incoming/{upload.filename}"
body="{upload.local_path}"/>
</upload>
Protects: the server is identified by its pinned certificate, so the collection cannot be sent to another server.
Does not protect: the password can be read from the collector. Use an account dedicated to uploads, unable to read or delete, and disable it after the engagement.
Chunked upload into Nextcloud¶
<upload method="rest" server="https://collect.mycorp.example" operation="copy"
authscheme="Basic" user="orc-upload" password="..."
https_security="tls1.3, tls1.2"
server_cert_pin="MIIDJTCCAg2gAwIBAgIU...">
<rest http_method="MKCOL" path="/remote.php/dav/files/orc-upload/incoming/" accept_status="405"/>
<rest http_method="MKCOL" path="/remote.php/dav/uploads/orc-upload/{upload.random:hex:16}"/>
<rest http_method="PUT" path="/remote.php/dav/uploads/orc-upload/{upload.random:hex:16}/{upload.range_start}"
body="{upload.local_path}" chunk_size="10485760"/>
<rest http_method="MOVE" path="/remote.php/dav/uploads/orc-upload/{upload.random:hex:16}/.file">
<header>Destination: /remote.php/dav/files/orc-upload/incoming/{upload.filename}</header>
</rest>
</upload>
Same protection as the previous example. Check that the file received is identical to the one collected.
S3 with a signed, scoped credential (AWS SigV4)¶
<upload method="rest" server="https://s3.mycorp.example" operation="copy"
https_security="tls1.3, tls1.2"
authscheme="AWSv4" access_key="..." secret_key="..." session_token="..."
aws_region="eu-west-3">
<rest http_method="PUT" path="/orc-bucket/incoming/{upload.filename}" body="{upload.local_path}"/>
</upload>
Protects: the credential can be revoked, and with session_token it expires on its own. Allow it only to write (s3:PutObject) to the upload folder.
Does not protect: until it expires, whoever holds the collector can write, and overwrite, in that folder: enable bucket versioning. Not available on Windows XP.
S3 with an anonymous write-only bucket¶
<upload method="rest" server="https://s3.mycorp.example" operation="copy"
https_security="tls1.3, tls1.2"
server_cert_pin="MIIDJTCCAg2gAwIBAgIU...">
<rest http_method="PUT" path="/orc-bucket/incoming/{upload.filename}" body="{upload.local_path}"/>
</upload>
Weaker than the signed form. There is no credential, but the bucket accepts writes from anyone who can reach it, who can then fill it or overwrite a collection. Only acceptable if the bucket allows writing and nothing else, versioning is enabled, and the server is reachable only from the collected network. A recipient is mandatory here.
Plain HTTP, for a laboratory only¶
<upload method="rest" server="http://127.0.0.1:8089" operation="copy" insecure="true">
<rest http_method="PUT" path="/up/{upload.filename}" body="{upload.local_path}"/>
</upload>
Never use this on a real collection. Nothing is encrypted and the server is not authenticated: anyone on the network path can read the collection. insecure="true" is required so this cannot happen by mistake.
recipient Element¶
optional=yes, default=N/A, parent element: dfir-orc
The recipient element is used to create the list of recipients able to open the enveloped CMS archives. It basically consists of a list of encoded certificates. This element is used to add a recipient’s certificate to the list of possible recipients for individual archives. This element implies encryption of the archives specified in its compulsory archive attribute.
Attributes¶
- name (optional=no, default=N/A)
Name of the recipient
- archive (optional=no, default=Does not encrypt any archive)
Comma separated list of archive keyword specs to match against archive names. Specifies one or more archives encrypted in a CMS PKCS#7 message (cf http://tools.ietf.org/html/rfc2315 )
It selects archives only: the outline, outcome, log and console output are encrypted for every recipient (see Decrypting a collection).
Example¶
<recipient name='certfr' archive='*' >
-----BEGIN CERTIFICATE-----
MIIC7TCCAdmgAwIBAgIQR5AF92Ti8qtEwuT3PMVrJzAJBgUrDgMCHQUAMBIxEDAO
BgNVBAMTB0NFUlQtRlIwHhcNMDQxMjMxMjIwMDAwWhcNMTQxMjMxMjIwMDAwWjAS
MRAwDgYDVQQDEwdDRVJULUZSMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKC
AQEAiufyRATXw5Kc/DUcEr/5nNygcbluyS5gkUd1pGaUqKHMSMEVOBzYqcvq3cMw
4shAL3TSgYdoOJaLG4ErvyRU87fWYRcwiHzGdFg89E3pBEWnyV3j3fR0fVB5t3MD
jbooTGI/qQGl1l3MZ+bOiHkYcIG50R5343VT5vjRLmPv16iopGczLXKkNFxN480f
BnCF8HcJesFiMIDUI+d9OWpLJNDSCerouMr75HVD47+gBKKgH2PrxWozk2L6R9gQ
l8/6xzM4VKiNt4BTGfChG8AnO8sJzPETjJaDXrIGaYVLxU4OxFh/a9x61dlM/5A/
TASXpLhXrsi+ib3YLLl+pNh+aQIDAQABo0cwRTBDBgNVHQEEPDA6gBD47GaJKs91
qsThQIQ7f8Y5oRQwEjEQMA4GA1UEAxMHQ0VSVC1GUoIQR5AF92Ti8qtEwuT3PMVr
JzAJBgUrDgMCHQUAA4IBAQBgvEE7qyLVV+Y5B0sR5VuPmfeqakOxBxLmb8VoTNKn
/7ai1XwtJeWD1vumKx5Q29GiUfVhvBgn0zhjM5syVDFCqEcp+eu6l2XbN8uvllCY
daTOT/9UylLxu1L/epiWiYtqRZOO/9i1fyqrkguIww7EjXXT3ybL5U/BakEC2Yg5
6vUoxbo2EbA1UoMWurRxYNYxyFfHpvBYXFf4uDaAFIVMtEgH5VkKyM3Kj2hi/PJH
/a30ndTWVSY/82hoRGCa+SkevR5VbDsxTqHtEHys4K+ETVTNXp29HwG+1YG7BTTc
4VdFRqUm7e3o6VUArFar8I01oHiHzqKJiu1Omm2Fkmc1
-----END CERTIFICATE-----
</recipient>
key Element¶
optional=yes, default=N/A, parent element: dfir-orc
The key element allows to select only specific commands to be executed or archives to be generated. All non-matching keywords or archives are not executed or generated. This element is exclusive with enable_key and disable_key.
Attributes¶
None
Example¶
<dfir-orc>
<key>ORC_Quick</ key>
<key>GetRam_winpmem1,Flashback</key>
</dfir-orc>
enable_key and disable_key Elements¶
optional=yes, default=N/A, parent element: dfir-orc
The enable_key element will enable an optional archive or command (cf. archive element , command element).
The disable_key element will disable an archive generation or command execution. Elements enable_key and disable_key can be combined and repeated. All enable_key elements take effect before the disable_key elements. Keywords are case insensitive. The data in the element can be a comma separated list of keywords.
Attributes¶
None
Example¶
<dfir-orc>
<disable_key>DFIR-ORC_Detail</disable_key>
<enable_key>GetRam_winpmem1</enable_key>
</dfir-orc>
log Element¶
optional=yes, default=N/A, parent element: dfir-orc
The log element can be used to create an optional log file of DFIR ORC execution. This file will be uploaded if an <upload/> element is specified in a DFIR ORC local configuration file.
The log message are passing through “sinks” like ‘console’ or ‘file’. To configure log output a sink must be specified.
Attributes¶
These two attributes are read on the log, console, outline and outcome elements of a local configuration, and override the embedded configuration, which is read before it. They are described once here.
- encrypt (optional=yes, default=the embedded configuration’s choice)
Set it to “no” to keep this file in clear text, even though the collection has a recipient and the embedded configuration encrypts it.
- upload (optional=yes, default=the embedded configuration’s choice)
Set it to “no” to keep this file on the host: it is still written, and encrypted as
encryptsays, but it is not sent to any upload.
Both attributes only ever turn something off. encrypt="yes" in a local configuration cannot re-encrypt a file the embedded configuration left in clear text, and upload="yes" cannot send one it kept on the host: a local configuration lowers what the collection was built to do and never raises it. Only “no”, “false” or “0” turns a switch off; any other value is read as yes and therefore changes nothing.
To add encryption locally, declare a recipient instead: these four files are encrypted for every recipient, including one declared here.
Each file that a local configuration takes out of the envelope the embedded configuration set up is named in the run’s own log, at warning level (Local configuration keeps the outcome in clear text). A collection’s own record leaving the host in clear text is a legitimate operator decision, but it should be visible as one, the way ToolEmbed reports clear text output at embedding time.
<dfir-orc>
<log encrypt="no"/>
<console encrypt="no"/>
<outline encrypt="no"/>
<outcome encrypt="no"/>
</dfir-orc>
Sinks¶
Console sink element, /log:console,... Option¶
optional=yes, default=N/A, parent element: log
level Attribute, /log:console,level=<Level>,... Option¶
optional=yes, default=critical, parent element: console
Log level is one of ‘trace’, ‘debug’, ‘info’ ‘error’, ‘warning’, ‘critical’.
backtrace Attribute, /log:console,backtrace=<Level>,... Option¶
optional=yes, default=off, parent element: console
Specify a log level which will trigger a log backtrace which will contain logs up to level ‘debug’.
Value is one of ‘trace’, ‘debug’, ‘info’ ‘error’, ‘warning’, ‘critical’, off.
File sink element, /log:file,... Option¶
optional=yes, default=N/A, parent element: log
The logging can be written to the file at the end of the tool execution. This implies that tool progress cannot be followed from log file using “tail
level Attribute, /log:file,level=<Level>,... Option¶
optional=yes, default=info, parent element: file
Log level is one of ‘trace’, ‘debug’, ‘info’ ‘error’, ‘warning’, ‘critical’.
backtrace Attribute, /log:file,backtrace=<Level>,... Option¶
optional=yes, default=error, parent element: file
Specify a log level which will trigger a log backtrace which will contain logs up to level ‘debug’.
Value is one of ‘trace’, ‘debug’, ‘info’ ‘error’, ‘warning’, ‘critical’, off.
output Element, /log:file,output=Path>,... Option¶
optional=yes, default=N/A, parent element: file
Path to the log file. Patterns are supported as with archive element (cf archive element).
Syslog sink element, /log:syslog,... Option¶
optional=yes, default=N/A, parent element: log
Redirect high level logs to a syslog server.
Currently ‘syslog’ use is restricted to WolfLauncher.
level Attribute, /log:syslog,level=<Level>,... Option¶
optional=yes, default=info, parent element: syslog
Log level is one of ‘trace’, ‘debug’, ‘info’ ‘error’, ‘warning’, ‘critical’.
backtrace Attribute, /log:syslog,backtrace=<Level>,... Option¶
optional=yes, default=off, parent element: syslog
Specify a log level which will trigger a log backtrace which will contain logs up to level ‘debug’.
Value is one of ‘trace’, ‘debug’, ‘info’ ‘error’, ‘warning’, ‘critical’, off.
host Attribute, /log:syslog,host=<ip4_or_ip6>,... Option¶
optional=no, default=N/A, parent element: syslog
Address of the syslog server
port Attribute, /log:syslog,port=<port>,... Option¶
optional=yes, default=514, parent element: syslog
Port of the syslog server.
Example¶
<log>
<console level="critical" backtrace="off"></console>
<file level="error" backtrace="error">
<output disposition="truncate">ORC_{SystemType}_{FullComputerName}_{TimeStamp}.dev.log</output>
</file>
<syslog>
<host>127.0.0.1</host>
<port>514</port>
</syslog>
</log>
dfir-orc.exe \
/log:console,level=critical,backtrace=off \
/log:file,level=debug,backtrace=error,output="dfir-orc.log" \
/log:syslog,host=127.0.0.1,port=514 ...
console Element¶
optional=yes, default=N/A, parent element: dfir-orc
Overrides the console output file - the tee of what the collection printed - configured by the console element of the embedded configuration.
Attributes¶
encrypt and upload, described under the log element.
Example¶
<console encrypt="no">
<output>ORC_{SystemType}_{FullComputerName}_{TimeStamp}_console.txt</output>
</console>
outline Element¶
optional=yes, default=N/A, parent element: dfir-orc
Overrides the outline file configured by the embedded configuration: where it is written, whether it is encrypted and whether it is uploaded. The inner text is the path, and supports the same patterns as an archive name; with no inner text the element carries only its attributes and the path configured at embedding time is kept.
Attributes¶
encrypt and upload, described under the log element.
Example¶
<outline encrypt="no">outline.json</outline>
outcome Element¶
optional=yes, default=N/A, parent element: dfir-orc
Overrides the outcome file configured by the embedded configuration, exactly as outline does for the outline.
Attributes¶
encrypt and upload, described under the log element.
Example¶
<outcome encrypt="no">outcome.json</outcome>