DFIR ORC Local Configuration File

DFIR ORC can be locally configured to specify a limited set of configuration elements. Typically, those elements are the client’s specific configuration options (like the upload method, priority, temporary folder, etc.). The local configuration can be specified using:

  • The /local=<LocalConfigFile> command-line option

  • A file in the same directory as DFIR ORC, with the same base name and .xml extension, e.g.:

    • <SomeDirectory>\\DFIR-Orc.exe

    • <SomeDirectory>\\DFIR-Orc.xml

The index of this sections consists in the following XML skeleton file, which features all the elements that can appear in a real configuration file. It is not a usable configuration, in the sense that it does not contain any attribute key or value, and can exhibit incompatible elements. Its point is to be exhaustive from the point of view of existing usable elements.

<dfir-orc attributes=”…”>
<output> value </output>
<upload attributes=”…”>
<header> value </header>
<rest attributes=”…”>
<header> value </header>
<response attributes=”…” />
<form attributes=”…” />
</rest>
<recipient attributes=”…”> value </recipient>
<key> value </key>
<log attributes=”…”> value </log>
<console attributes=”…”> value </console>
<outline attributes=”…”> value </outline>
<outcome attributes=”…”> value </outcome>

dfir-orc Element

optional=no, default=N/A

Root element

Attributes

  • priority (optional=yes, default=normal)

    Configures Windows process (and thread) priority class. Available values for this attribute are: Low, Normal & High.

  • powerstate (optional=yes, default=unmodified power state)

    Configures DFIR ORC’s main thread power state to optionally prevent the system from going to sleep when DFIR ORC is running. Allowed value is a comma separated list of

    • SystemRequired

    • Displayrequired

    • UserPresent

    • AwayMode.

    When only looking to prevent sleep, recommended value for this option is SystemRequired,AwayMode. More information on power states: https://docs.microsoft.com/en-us/windows/desktop/api/winbase/nf-winbase-setthreadexecutionstate

Back to Root

temporary Element

optional=yes, default=%temp%, parent element: dfir-orc

This element configures the location of temporary files created by the tool. The inner text of this element contains the name of the folder. Environment variables will be substituted.

Attributes

None

Example

<temporary>%Temp%\WorkingTemp</temporary>

Back to Root

output Element

optional=no, default=’.’, parent element: dfir-orc

This element configures the folder where the various archives will be created. A local drive or a remote SMB share can be specified (in the latter, the upload syntax should be privileged to reduce network congestion). Environment variables will be substituted.

Attributes

None

Example

<output>%Temp%</output>

Back to Root

upload Element

optional=yes, default=no upload, parent element: dfir-orc

The upload element is used to configure an optional upload operation when an archive is created.

Attributes

  • job (optional=yes, default=none)

    Describes the upload operation.

  • method (optional=no, default=N/A)

    Describes the method to upload the files: “filecopy” (uses SMB), “BITS”, or “rest” (HTTP/HTTPS, see REST upload).

  • server (optional=no, default=N/A)

    Specifies the server name (e.g. file://servername or http://servername, or https://servername) when using BITS or SMB.

    For “rest”, a scheme and a host, optionally with a port, e.g. https://servername:8443. The path is given in the rest element.

  • uri (optional=yes, default=N/A)

    The destination as a single URL, e.g. https://user:password@servername/upload, instead of server, path, user and password.

  • path (optional=no, default= / or \ depending on the method)

    Specifies the file share or folder for the upload

  • user (optional=yes, default=the current user (executing DFIR ORC))

    Specifies the user name to be used to connect to the remote server.

  • password (optional=yes, default=N/A)

    Specifies the password to use (for the user defined above)

  • authscheme (optional=yes, default=Negotiate (if a user name is specified, anonymous otherwise))

    Specifies the authentication scheme for the connection. Possible scheme values are:

    • Anonymous

    • Basic

    • NTLM

    • Kerberos

    • Negotiate

    • AWSv4 (method="rest" only, see AWS SigV4)

  • operation (optional=yes, default=copy)

    “copy” or “move” the archives to the upload server. With “move”, the local file is deleted once it has been sent.

  • retry (optional=yes, default=0)

    Number of extra attempts at this entry before trying the next one: retry="2" means three attempts. At most 10. Retries take place at the end of the collection. No effect with mode="async".

  • retry_delay (optional=yes, default=30)

    Seconds between two attempts. At most 1800, and retry x retry_delay may not exceed 1800 seconds.

  • mode (optional=yes, default=sync)

    “sync” or “async”: upload can be synchronous or asynchronous (asynchronous allows DFIR ORC to exit prior to BITS jobs completes). “async” is not supported for “filecopy” method.

  • include (optional=yes, default=none)

    Specifies a comma (or semicolon) separated list of patterns, matching the file name of archives, that determine whether an output archive from DFIR-Orc.exe will be uploaded to the specified location. When missing, all archives are uploaded (if not explicitly excluded, see below). When specified, only archives whose name matches one of the patterns will be uploaded.

  • exclude (optional=yes, default=none)

    Specifies a comma (or semicolon) separated list of patterns, matching the file name of archives, that determine whether an output archive should not be uploaded. When excluded, an output archive is left intact in the output directory (i.e. regardless of the operation attribute). The exclude attribute takes precedence over the include attribute, meaning an archive whose name matches both include and exclude patterns will be excluded.

  • delete_smb_share (optional=yes, default=none)

    Currently only available for BITS over SMB. When set to “true” the connection to the share will be deleted at the end of jobs (with the use of net use /del). This option should only be needed when the share is served by Samba.

include and exclude select collected data: the archives produced by the commands. The run’s own files - the log, the console output, the outline and the outcome - are not affected by these filters.

Several upload elements may be declared. They form a fallback list, tried in order until one succeeds, and each entry is used with its own operation and its own include/exclude: a fallback that says operation="copy" keeps the local archive even when the first entry asked to move it, and one that excludes a file does not receive it.

The filters are per destination, in both directions: a file the first entry excludes is still offered to a later entry that accepts it. exclude says “this destination does not take that archive”, not “this archive stays on the machine” - to keep a file from leaving at all, it must be excluded from every entry.

An entry that cannot be configured is skipped, as long as another entry remains usable.

The upload entries of a local configuration are added after those of the embedded configuration, as further fallbacks. Before DFIR ORC 10.4.0, they replaced them.

Example

<upload job="DFIR-ORC" method="BITS"
  server="http://MyBits.MyOrg.com"
  path="upload"
  user="MyORG\BITSUploadClient" password="P@ssw0rd!"
  operation="move"
  include="DFIR-ORC_*_Hives.7z" />

REST upload

With method="rest" the archives are uploaded over HTTP or HTTPS. The requests are described by rest child elements: a single PUT, or the dialog of a server such as WebDAV, Nextcloud or S3 (see REST server dialogs).

Warning

The REST method is new and has only been tested in a laboratory. Before relying on it, run a complete collection against your own server.

The following attributes apply to this method only.

Transport security

  • https_security (optional=yes, default=”tls1.3, tls1.2[xp]”)

    Minimum TLS version, as a comma separated list of “tls1.0” to “tls1.3”: the version given and every higher one are allowed. A version followed by “[xp]” or “[seven]” applies to that system only. “os-default” keeps the system settings, still requiring TLS 1.2 or higher; “os-max” uses only the highest version the system supports.

    The default requires TLS 1.3, or TLS 1.2 on Windows XP and 2003.

  • server_cert_pin (optional=yes, default=none)

    One or more certificates, PEM or base64, separated by commas. The server is accepted only if the public key of its certificate matches one of them. This is the way to use a self-signed server. Give several certificates to allow a key change.

  • insecure (optional=yes, default=false)

    Allows plain HTTP and TLS below 1.2, and disables certificate validation. For a laboratory only; prefer server_cert_pin.

  • follow_redirects (optional=yes, default=false)

    Follows HTTP redirections. Off by default, since a redirection would send the credentials to another server.

Authentication

The scheme is given by authscheme:

  • Basic - with user and password.

  • NTLM, Kerberos, Negotiate - with user and password. The account DFIR ORC runs under is never used.

  • AWSv4 - see AWS SigV4.

  • A token, e.g. Bearer - written as a header, see below.

Use an account dedicated to uploads, that can be revoked: the credentials embedded in the collector can be read by whoever obtains it.

AWS SigV4

authscheme="AWSv4" signs each request as an S3 server expects: AWS S3, or a compatible server such as MinIO, RustFS or SeaweedFS.

Attribute

Required

Meaning

access_key

yes

the access key

secret_key

yes

the secret key

session_token

no

the session token of a temporary credential

aws_region

yes

the region, e.g. eu-west-3

aws_service

no (default s3)

the service name

aws_clock

no (default local)

server uses the server’s time when the local clock is wrong

  • The keys are used as written: environment variables are not expanded in them. A temporary credential, with session_token, avoids embedding a permanent secret.

  • Write the path as plain text, e.g. a space as a space, not encoded as %20.

  • Redirections are not followed.

  • Not available on Windows XP and 2003.

<upload job="DFIR-ORC" method="rest"
  server="https://s3.mycorp.example"
  operation="move"
  authscheme="AWSv4"
  access_key="AKIA..." secret_key="..." aws_region="eu-west-3">
    <rest http_method="PUT" path="/orc-bucket/incoming/{upload.filename}" body="{upload.local_path}"/>
</upload>

Headers sent with every request

  • http_header (optional=yes, default=none)

    One header line, sent with every request, e.g. http_header="Authorization: Bearer &lt;token&gt;".

To send several headers, use header child elements of upload, one line each:

<upload method="rest" server="https://collect.mycorp.example">
    <header>Authorization: Bearer eyJhbGciOi...</header>
    <header>X-Collection: nightly</header>
    <rest http_method="PUT" path="/incoming/{upload.filename}" body="{upload.local_path}"/>
</upload>

A header inside a rest element is sent with that request only. Headers may use the placeholders below.

Proxy

  • proxy (optional=yes, default=the machine proxy settings)

    How the proxy is found:

    Value

    Meaning

    (attribute absent)

    the machine proxy settings (netsh winhttp)

    "" / direct / none

    no proxy

    system

    the machine proxy settings

    wpad / auto

    automatic discovery (WPAD)

    pac:<url> or <url>.pac

    a PAC script

    host:port

    this proxy

  • proxy_bypass (optional=yes, default=none)

    Hosts reached without the proxy, e.g. <local>;*.corp.

  • proxy_user, proxy_password (optional=yes, default=none)

    Credentials for the proxy. proxy must be set, e.g. to “system”. Use an account dedicated to the proxy.

  • proxy_authscheme (optional=yes, default=Anonymous)

    “Basic”, “NTLM” or “Negotiate”. For NTLM and Negotiate, give a domain user, e.g. DOMAIN\user.

Placeholders

The path, http_query, body and offset attributes of a rest element, and its headers, may use these placeholders:

Placeholder

Description

{upload.filename}

name of the file

{upload.filename_base64}

name of the file, base64 encoded

{upload.local_path}

local path of the file

{upload.range_start}

offset of the chunk being sent

{upload.range_end}

offset of the last byte of the chunk

{upload.range_length}

length of the chunk

{upload.total_size}

size of the file

{upload.random:<charset>:<length>}

a random string, the same for the whole file; charset is hex, num, alpha or alnum, length is 1 to 64

A value captured with a response element is written {name}.

REST example

Warning

Understand each parameter before using a configuration: a wrong setting can make the upload insecure, for instance by sending the collection in clear text or to another server.

<upload job="DFIR-ORC" method="rest"
  server="https://collect.mycorp.example"
  operation="move"
  proxy="system" proxy_authscheme="NTLM" proxy_user="MYCORP\orc-proxy" proxy_password="P@ssw0rd!"
  server_cert_pin="MIIDLDCCAhSgAwIBAgIU...">
    <rest http_method="PUT" path="/incoming/{upload.filename}" body="{upload.local_path}"
          chunk_size="1048576">
        <header>Content-Range: bytes {upload.range_start}-{upload.range_end}/{upload.total_size}</header>
    </rest>
</upload>

A resumable upload asks the server what it already holds, then starts from there:

<upload method="rest" server="https://collect.mycorp.example" operation="move">
    <rest http_method="HEAD" path="/incoming/{upload.filename}" accept_status="404">
        <response header="content-length" name="remote_size" default="0"/>
    </rest>
    <rest http_method="PUT" path="/incoming/{upload.filename}" body="{upload.local_path}"
          offset="{remote_size}" chunk_size="1048576">
        <header>Content-Range: bytes {upload.range_start}-{upload.range_end}/{upload.total_size}</header>
    </rest>
</upload>

More examples, for each tested server, are in the tests/RestAgent directory of the source tree.

rest Element

optional=yes, default=N/A, parent element: upload

Describes one request sent by method="rest". Requests are sent in the order they are declared; one of them sends the file.

Attributes

  • http_method (optional=no, default=N/A)

    The HTTP verb, e.g. “PUT”, “POST”, “PATCH”, “HEAD”, “MKCOL”, “MOVE”.

  • path (optional=no, default=N/A)

    Path of the request on the server, as a template.

  • http_query (optional=yes, default=none)

    Query string appended to the path, as a template, e.g. ?start={upload.range_start}.

  • body (optional=yes, default=no body)

    The file to send, normally {upload.local_path}.

  • offset (optional=yes, default=0)

    Where to start in the file, e.g. {remote_size} captured by a previous step, to resume an upload.

  • chunk_size (optional=yes, default=the whole file in one request)

    Sends the file in chunks of that many bytes. Required beyond 4 GB. Each chunk must be identified by {upload.range_start} in the path, the query or a header.

  • accept_status (optional=yes, default=any 2xx)

    Additional HTTP status codes to treat as success, comma separated, e.g. 404 on a probe that legitimately finds nothing.

  • session (optional=yes, default=once per file)

    session="once" runs the step only once, before the first file, instead of once per file: for a login. Cookies set by the server are kept for the following steps.

header child element

One header line, sent with this request only. Repeat the element for several headers.

response child element

Captures a value from the server’s answer to this step, for later steps to use. Each response reads exactly one of header, form_input, attribute or dav_property.

  • name (optional=no, default=N/A)

    Name of the captured value, written {name} in a later step. It cannot start with upload..

  • header (optional=yes, default=none)

    Name of the response header to capture.

  • form_input (optional=yes, default=none)

    Name of an HTML <input> - typically a hidden token - whose value is read from the returned page.

  • attribute (optional=yes, default=none)

    Name of an HTML attribute whose value is read from the returned page, e.g. data-requesttoken.

    If form_input or attribute finds nothing and no default is given, the upload stops.

  • dav_property (optional=yes, default=none)

    Name of a WebDAV property read from a PROPFIND answer, e.g. getcontentlength. Not available in the standard build.

  • default (optional=yes, default=empty)

    Value used when the server does not return the header, property, input or attribute.

form child element

One field of a form sent as the request body, e.g. the password of a login form. Repeat the element for several fields.

  • field (optional=no, default=N/A)

    Name of the field.

  • value (optional=no, default=N/A)

    Value of the field. It may use a value captured by an earlier step, e.g. {rt}.

The step must use POST, PUT or PATCH, and cannot also carry body.

<upload method="rest" server="https://share.mycorp.example" operation="copy">
    <rest http_method="GET" path="/s/SHARETOKEN" session="once">
        <response form_input="requesttoken" name="rt"/>
    </rest>
    <rest http_method="POST" path="/s/SHARETOKEN" session="once" accept_status="302,303">
        <form field="password"     value="a-scoped-share-password"/>
        <form field="requestToken" value="{rt}"/>
    </rest>
    <rest http_method="PUT" path="/public.php/dav/files/SHARETOKEN/{upload.filename}"
          body="{upload.local_path}"/>
</upload>

The two login steps run once; the files are then sent with the session they opened. See REST configuration examples for the form login of Nextcloud.

Back to Root

REST server dialogs

The rest elements describe requests, not a protocol: another server can be used by writing its own sequence of requests. These dialogs have been tested:

Dialog

Steps

Where it has been exercised

Single PUT

one body step

the reference sink, Nextcloud 35, MinIO, RustFS, SeaweedFS

Chunked

one body step with chunk_size, the offset in the path, the query or a Content-Range header

the reference sink

Resume

a HEAD probe capturing content-length into {remote_size}, then a body step with offset="{remote_size}"

the reference sink

WebDAV

MKCOL (with accept_status="405"), the body step under a temporary name, then MOVE to the final name

the reference sink, Nextcloud 35

Nextcloud chunked upload v2

MKCOL the collection, MKCOL an upload directory named by {upload.random:...}, one chunk PUT per {upload.range_start}, then MOVE

Nextcloud 35

S3

one PUT per object, anonymous or signed (AWS SigV4)

MinIO, RustFS, SeaweedFS

  • A PUT replaces the file: resuming only works with a server that appends. With Nextcloud or S3, an interrupted upload starts again from the beginning.

  • Chunks are named by their offset, and the server must sort them as numbers. Nextcloud 35 does.

  • With S3, a file is sent in a single request, which limits it to 5 GB.

The test configurations for these servers are in tests/RestAgent of the source tree.

Back to Root

REST configuration examples

Warning

These examples show the syntax. They are not equally secure: each one says what it protects and what it does not. Do not reuse one without understanding it.

The collector may run on a compromised host: its configuration, credentials included, can be read.

Question

Stronger

Weaker

Is the server authenticated?

server_cert_pin, or a trusted certificate

insecure="true", plain HTTP

What can the embedded credential do?

only write, revocable, short-lived

anonymous write; read or delete rights

Is the collection encrypted?

a recipient is configured

no recipient

Configure a recipient with every example below.

HTTPS with a pinned certificate and a scoped account (WebDAV, Nextcloud)

<upload method="rest" server="https://collect.mycorp.example" operation="copy"
        authscheme="Basic" user="orc-upload" password="..."
        https_security="tls1.3, tls1.2"
        server_cert_pin="MIIDJTCCAg2gAwIBAgIU...">
    <rest http_method="MKCOL" path="/remote.php/dav/files/orc-upload/incoming/" accept_status="405"/>
    <rest http_method="PUT" path="/remote.php/dav/files/orc-upload/incoming/{upload.filename}"
          body="{upload.local_path}"/>
</upload>

Protects: the server is identified by its pinned certificate, so the collection cannot be sent to another server.

Does not protect: the password can be read from the collector. Use an account dedicated to uploads, unable to read or delete, and disable it after the engagement.

Chunked upload into Nextcloud

<upload method="rest" server="https://collect.mycorp.example" operation="copy"
        authscheme="Basic" user="orc-upload" password="..."
        https_security="tls1.3, tls1.2"
        server_cert_pin="MIIDJTCCAg2gAwIBAgIU...">
    <rest http_method="MKCOL" path="/remote.php/dav/files/orc-upload/incoming/" accept_status="405"/>
    <rest http_method="MKCOL" path="/remote.php/dav/uploads/orc-upload/{upload.random:hex:16}"/>
    <rest http_method="PUT" path="/remote.php/dav/uploads/orc-upload/{upload.random:hex:16}/{upload.range_start}"
          body="{upload.local_path}" chunk_size="10485760"/>
    <rest http_method="MOVE" path="/remote.php/dav/uploads/orc-upload/{upload.random:hex:16}/.file">
        <header>Destination: /remote.php/dav/files/orc-upload/incoming/{upload.filename}</header>
    </rest>
</upload>

Same protection as the previous example. Check that the file received is identical to the one collected.

S3 with a signed, scoped credential (AWS SigV4)

<upload method="rest" server="https://s3.mycorp.example" operation="copy"
        https_security="tls1.3, tls1.2"
        authscheme="AWSv4" access_key="..." secret_key="..." session_token="..."
        aws_region="eu-west-3">
    <rest http_method="PUT" path="/orc-bucket/incoming/{upload.filename}" body="{upload.local_path}"/>
</upload>

Protects: the credential can be revoked, and with session_token it expires on its own. Allow it only to write (s3:PutObject) to the upload folder.

Does not protect: until it expires, whoever holds the collector can write, and overwrite, in that folder: enable bucket versioning. Not available on Windows XP.

S3 with an anonymous write-only bucket

<upload method="rest" server="https://s3.mycorp.example" operation="copy"
        https_security="tls1.3, tls1.2"
        server_cert_pin="MIIDJTCCAg2gAwIBAgIU...">
    <rest http_method="PUT" path="/orc-bucket/incoming/{upload.filename}" body="{upload.local_path}"/>
</upload>

Weaker than the signed form. There is no credential, but the bucket accepts writes from anyone who can reach it, who can then fill it or overwrite a collection. Only acceptable if the bucket allows writing and nothing else, versioning is enabled, and the server is reachable only from the collected network. A recipient is mandatory here.

Form login into a Nextcloud public share

<upload method="rest" server="https://share.mycorp.example" operation="copy"
        https_security="tls1.3, tls1.2"
        server_cert_pin="MIIDJTCCAg2gAwIBAgIU...">
    <rest http_method="GET" path="/s/SHARETOKEN/authenticate/showshare" session="once">
        <response attribute="data-requesttoken" name="rt1"/>
    </rest>
    <rest http_method="POST" path="/s/SHARETOKEN/authenticate/showshare"
          session="once" accept_status="302,303">
        <header>requesttoken: {rt1}</header>
        <form field="password"     value="SHARE-PASSWORD"/>
        <form field="sharingToken" value="SHARETOKEN"/>
        <form field="sharingType"  value="3"/>
    </rest>
    <rest http_method="GET" path="/s/SHARETOKEN" session="once">
        <response attribute="data-requesttoken" name="rt2"/>
    </rest>
    <rest http_method="PUT" path="/public.php/dav/files/SHARETOKEN/{upload.filename}"
          body="{upload.local_path}">
        <header>requesttoken: {rt2}</header>
        <header>X-Requested-With: XMLHttpRequest</header>
        <header>Origin: https://share.mycorp.example</header>
    </rest>
</upload>

Protects: no user account is embedded, and deleting the share revokes access.

Does not protect: the share token and password can be read from the collector. If the share lets visitors see or download its content, they give access to every collection. This was tested with a password-protected share only, and may break with a Nextcloud update.

Plain HTTP, for a laboratory only

<upload method="rest" server="http://127.0.0.1:8089" operation="copy" insecure="true">
    <rest http_method="PUT" path="/up/{upload.filename}" body="{upload.local_path}"/>
</upload>

Never use this on a real collection. Nothing is encrypted and the server is not authenticated: anyone on the network path can read the collection. insecure="true" is required so this cannot happen by mistake.

Back to Root

recipient Element

optional=yes, default=N/A, parent element: dfir-orc

The recipient element is used to create the list of recipients able to open the enveloped CMS archives. It basically consists of a list of encoded certificates. This element is used to add a recipient’s certificate to the list of possible recipients for individual archives. This element implies encryption of the archives specified in its compulsory archive attribute.

Attributes

  • name (optional=no, default=N/A)

    Name of the recipient

  • archive (optional=no, default=Does not encrypt any archive)

    Comma separated list of archive keyword specs to match against archive names. Specifies one or more archives encrypted in a CMS PKCS#7 message (cf http://tools.ietf.org/html/rfc2315 )

    It selects archives only: the outline, outcome, log and console output are encrypted for every recipient (see Decrypting a collection).

Example

<recipient name='certfr' archive='*' >
  -----BEGIN CERTIFICATE-----
  MIIC7TCCAdmgAwIBAgIQR5AF92Ti8qtEwuT3PMVrJzAJBgUrDgMCHQUAMBIxEDAO
  BgNVBAMTB0NFUlQtRlIwHhcNMDQxMjMxMjIwMDAwWhcNMTQxMjMxMjIwMDAwWjAS
  MRAwDgYDVQQDEwdDRVJULUZSMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKC
  AQEAiufyRATXw5Kc/DUcEr/5nNygcbluyS5gkUd1pGaUqKHMSMEVOBzYqcvq3cMw
  4shAL3TSgYdoOJaLG4ErvyRU87fWYRcwiHzGdFg89E3pBEWnyV3j3fR0fVB5t3MD
  jbooTGI/qQGl1l3MZ+bOiHkYcIG50R5343VT5vjRLmPv16iopGczLXKkNFxN480f
  BnCF8HcJesFiMIDUI+d9OWpLJNDSCerouMr75HVD47+gBKKgH2PrxWozk2L6R9gQ
  l8/6xzM4VKiNt4BTGfChG8AnO8sJzPETjJaDXrIGaYVLxU4OxFh/a9x61dlM/5A/
  TASXpLhXrsi+ib3YLLl+pNh+aQIDAQABo0cwRTBDBgNVHQEEPDA6gBD47GaJKs91
  qsThQIQ7f8Y5oRQwEjEQMA4GA1UEAxMHQ0VSVC1GUoIQR5AF92Ti8qtEwuT3PMVr
  JzAJBgUrDgMCHQUAA4IBAQBgvEE7qyLVV+Y5B0sR5VuPmfeqakOxBxLmb8VoTNKn
  /7ai1XwtJeWD1vumKx5Q29GiUfVhvBgn0zhjM5syVDFCqEcp+eu6l2XbN8uvllCY
  daTOT/9UylLxu1L/epiWiYtqRZOO/9i1fyqrkguIww7EjXXT3ybL5U/BakEC2Yg5
  6vUoxbo2EbA1UoMWurRxYNYxyFfHpvBYXFf4uDaAFIVMtEgH5VkKyM3Kj2hi/PJH
  /a30ndTWVSY/82hoRGCa+SkevR5VbDsxTqHtEHys4K+ETVTNXp29HwG+1YG7BTTc
  4VdFRqUm7e3o6VUArFar8I01oHiHzqKJiu1Omm2Fkmc1
  -----END CERTIFICATE-----
</recipient>

Back to Root

key Element

optional=yes, default=N/A, parent element: dfir-orc

The key element allows to select only specific commands to be executed or archives to be generated. All non-matching keywords or archives are not executed or generated. This element is exclusive with enable_key and disable_key.

Attributes

None

Example

<dfir-orc>
  <key>ORC_Quick</ key>
  <key>GetRam_winpmem1,Flashback</key>
</dfir-orc>

Back to Root

enable_key and disable_key Elements

optional=yes, default=N/A, parent element: dfir-orc

The enable_key element will enable an optional archive or command (cf. archive element , command element). The disable_key element will disable an archive generation or command execution. Elements enable_key and disable_key can be combined and repeated. All enable_key elements take effect before the disable_key elements. Keywords are case insensitive. The data in the element can be a comma separated list of keywords.

Attributes

None

Example

<dfir-orc>
    <disable_key>DFIR-ORC_Detail</disable_key>
    <enable_key>GetRam_winpmem1</enable_key>
</dfir-orc>

Back to Root

log Element

optional=yes, default=N/A, parent element: dfir-orc

The log element can be used to create an optional log file of DFIR ORC execution. This file will be uploaded if an <upload/> element is specified in a DFIR ORC local configuration file.

The log message are passing through “sinks” like ‘console’ or ‘file’. To configure log output a sink must be specified.

Attributes

These two attributes are read on the log, console, outline and outcome elements of a local configuration, and override the embedded configuration, which is read before it. They are described once here.

  • encrypt (optional=yes, default=the embedded configuration’s choice)

    Set it to “no” to keep this file in clear text, even though the collection has a recipient and the embedded configuration encrypts it.

  • upload (optional=yes, default=the embedded configuration’s choice)

    Set it to “no” to keep this file on the host: it is still written, and encrypted as encrypt says, but it is not sent to any upload.

Both attributes only ever turn something off. encrypt="yes" in a local configuration cannot re-encrypt a file the embedded configuration left in clear text, and upload="yes" cannot send one it kept on the host: a local configuration lowers what the collection was built to do and never raises it. Only “no”, “false” or “0” turns a switch off; any other value is read as yes and therefore changes nothing.

To add encryption locally, declare a recipient instead: these four files are encrypted for every recipient, including one declared here.

Each file that a local configuration takes out of the envelope the embedded configuration set up is named in the run’s own log, at warning level (Local configuration keeps the outcome in clear text). A collection’s own record leaving the host in clear text is a legitimate operator decision, but it should be visible as one, the way ToolEmbed reports clear text output at embedding time.

<dfir-orc>
    <log encrypt="no"/>
    <console encrypt="no"/>
    <outline encrypt="no"/>
    <outcome encrypt="no"/>
</dfir-orc>

Sinks

Console sink element, /log:console,... Option

optional=yes, default=N/A, parent element: log

level Attribute, /log:console,level=<Level>,... Option

optional=yes, default=critical, parent element: console

Log level is one of ‘trace’, ‘debug’, ‘info’ ‘error’, ‘warning’, ‘critical’.

backtrace Attribute, /log:console,backtrace=<Level>,... Option

optional=yes, default=off, parent element: console

Specify a log level which will trigger a log backtrace which will contain logs up to level ‘debug’.

Value is one of ‘trace’, ‘debug’, ‘info’ ‘error’, ‘warning’, ‘critical’, off.

File sink element, /log:file,... Option

optional=yes, default=N/A, parent element: log

The logging can be written to the file at the end of the tool execution. This implies that tool progress cannot be followed from log file using “tail

level Attribute, /log:file,level=<Level>,... Option

optional=yes, default=info, parent element: file

Log level is one of ‘trace’, ‘debug’, ‘info’ ‘error’, ‘warning’, ‘critical’.

backtrace Attribute, /log:file,backtrace=<Level>,... Option

optional=yes, default=error, parent element: file

Specify a log level which will trigger a log backtrace which will contain logs up to level ‘debug’.

Value is one of ‘trace’, ‘debug’, ‘info’ ‘error’, ‘warning’, ‘critical’, off.

output Element, /log:file,output=Path>,... Option

optional=yes, default=N/A, parent element: file

Path to the log file. Patterns are supported as with archive element (cf archive element).

Syslog sink element, /log:syslog,... Option

optional=yes, default=N/A, parent element: log

Redirect high level logs to a syslog server.

Currently ‘syslog’ use is restricted to WolfLauncher.

level Attribute, /log:syslog,level=<Level>,... Option

optional=yes, default=info, parent element: syslog

Log level is one of ‘trace’, ‘debug’, ‘info’ ‘error’, ‘warning’, ‘critical’.

backtrace Attribute, /log:syslog,backtrace=<Level>,... Option

optional=yes, default=off, parent element: syslog

Specify a log level which will trigger a log backtrace which will contain logs up to level ‘debug’.

Value is one of ‘trace’, ‘debug’, ‘info’ ‘error’, ‘warning’, ‘critical’, off.

host Attribute, /log:syslog,host=<ip4_or_ip6>,... Option

optional=no, default=N/A, parent element: syslog

Address of the syslog server

port Attribute, /log:syslog,port=<port>,... Option

optional=yes, default=514, parent element: syslog

Port of the syslog server.

Example

<log>
    <console level="critical" backtrace="off"></console>
    <file level="error" backtrace="error">
        <output disposition="truncate">ORC_{SystemType}_{FullComputerName}_{TimeStamp}.dev.log</output>
    </file>
    <syslog>
        <host>127.0.0.1</host>
        <port>514</port>
    </syslog>
</log>
dfir-orc.exe \
    /log:console,level=critical,backtrace=off \
    /log:file,level=debug,backtrace=error,output="dfir-orc.log" \
    /log:syslog,host=127.0.0.1,port=514 ...

Back to Root

console Element

optional=yes, default=N/A, parent element: dfir-orc

Overrides the console output file - the tee of what the collection printed - configured by the console element of the embedded configuration.

Attributes

encrypt and upload, described under the log element.

Example

<console encrypt="no">
    <output>ORC_{SystemType}_{FullComputerName}_{TimeStamp}_console.txt</output>
</console>

Back to Root

outline Element

optional=yes, default=N/A, parent element: dfir-orc

Overrides the outline file configured by the embedded configuration: where it is written, whether it is encrypted and whether it is uploaded. The inner text is the path, and supports the same patterns as an archive name; with no inner text the element carries only its attributes and the path configured at embedding time is kept.

Attributes

encrypt and upload, described under the log element.

Example

<outline encrypt="no">outline.json</outline>

Back to Root

outcome Element

optional=yes, default=N/A, parent element: dfir-orc

Overrides the outcome file configured by the embedded configuration, exactly as outline does for the outline.

Attributes

encrypt and upload, described under the log element.

Example

<outcome encrypt="no">outcome.json</outcome>

Back to Root