Windows
 
Mac
 
Linux
 
iPhone
 
iPad
 
Android

RSS Feeds

Receive a regular RSS feed from our latest, most popular and recommended downloads

Latest downloads feed

Get a regular RSS from our most latest downloads

Most popular downloads feed

Get a regular RSS from our most popular downloads

Recommended downloads feed

Get a regular RSS from our recommended downloads

Newsletter

Subscribe to either one of our two newsletters for regular updates and information

Downloads newsletter

This is a weekly newsletter with download news, updates and other information

This is a monthly newsletter with software store information, offers and deals

AChoir 0.96a

Collect detailed forensic data on any PC

by Mike Williams

Our Rating:
Your Rating:
Login to rate
Based on 0 ratings
License: Open Source
Operating Systems: Windows 10, Windows 7 (32 bit), Windows 7 (64 bit), Windows 8
Requirements:
Languages: English
Software Cost: Free
Date Updated: 15 April 2017
Watchlist: Add download to my watchlist
Downloads To Date: 520
Developer: OMENScan
RSS News Feed:
Back up your data with Acronis True Image 2016 with a 1-PC LIFETIME license, only $34.99, saving 50%, from store.pcauthority.com.au
AChoir
Collect detailed forensic data on any PC

AChoir is a scriptable open-source tool which enables collecting a host of forensic data on a target PC.

The details include basic system and hardware information, installed applications, drivers, user groups and accounts, network adapters, running processes (copies of the executables, not just the names), currently open network connections, browsing history, and raw data including dumps of RAM, NTFS data (MFT, UsnJrnl etc), event logs, Registry hives and more.

AChoir assembles most of this information with the help of other free or open-source tools, including AutoRuns to find your startup programs, and NirSoft's LastActivityView to build a timeline of the user's recent actions.

You don't need to have any of these tools in advance, AChoir doesn't break any license by bundling programs itself. Instead, when you first run AChoir-inst.exe, the program automatically downloads everything it needs. (The "Install" just collects all the files you need in a single folder tree. Make this a USB key and you've created a portable toolkit you can run anywhere.)

When you're ready, running AChoir.exe or AChoir64.exe in the installation folder will start the data collection process. This takes a while, and requires a lot of space, mostly due to the complete RAM dump. HTML reports and copies of the various data files are stored in a local folder.

This all ran smoothly when we tried it, but the key point of AChoir is that it's all controlled via custom scripts. Here's a very small part from the default file:

SAY: 10. Gathering Running Process List Information...
SAY:
SYS:Tasklist /v > &Acq\Tasklist.dat
SYS:Tasklist /M > &Acq\TaskAll.dat
SYS:\SYS\PSList.exe /accepteula -x > &Acq\PSList.dat

The "SAY" and "SYS" commands are displaying prompts or running actions, and everything else is essentially just a batch file. AChoir is using the built-in TaskList command to record details of running tasks, SysInternals' PsList to capture more, and redirecting the output of both to a report file.

This makes it extremely easy to reconfigure the program. Don't need the full memory dump? Delete those lines. Want to use some other NirSoft tool, instead? Find the command line switches you need and add it to the script.

* AChoir v0.55 - Add LST: - Looping Object (&LST) that reads entries from a file. Also Add SID (file owner) copy on the CPY: command.

Verdict:

AChoir isn't for beginners, but if you need to collect a lot of data on a PC then it's a solid and configurable way to start.

Your Comments & Opinion
 
Related Download Articles
 
JPEGSnoop

JPEGSnoop 1.7.5

Open Source

Has a JPEG image been edited? Here's one way to find out (maybe)

ExecutedProgramsList

ExecutedProgramsList 1.11

Freeware

See which programs have been run on a PC

WinPrefetchView (64-bit)

WinPrefetchView 1.35 (64-bit)

Freeware

Troubleshoot program startup problems

WinPrefetchView (32-bit)

WinPrefetchView 1.35

Freeware

Troubleshoot program startup problems

Other Download Articles From This Category
Kaspersky Total Security 2018

Kaspersky Total Security 2018 v18.0.0.405

Trial Software

A comprehensive, reliable and accurate security suite for all your devices

Kaspersky Anti-Virus 2018

Kaspersky Anti-Virus 2018

Trial Software

Kaspersky's latest offers great malware protection

Kaspersky Internet Security 2018

Kaspersky Internet Security 2018 18.0.0.405

Trial Software

Kaspersky's powerhouse security suite

Hotspot Shield 6

Hotspot Shield 6.7.2

Freeware

Protect your computer and enjoy unrestricted internet access when using wifi hotspots

PC & Tech Authority Software News

Please wait while my feed loads

See more posts...

Our Price: $19.95
RRP: $49.99
Saving 60%
Buy Now
Offer Ends In:
 

Spotlight: Free Full Software

Unreal Engine 4.15.1

Free Full Commercial Software

Unreal Engine is Epic Games' game engine, a powerful suite of tools for developing anything from basic 2D games to professional RPGs, first person shooters and whatever else you like.

Wide standards support - DirectX, OpenGL, JavaScript/ WebGL - means your projects can be targeted to almost any platform: consoles, iOS, Android, Windows, OS X, Linux, HTML5 browsers and more.

There's a vast amount to learn, of course, and that's even before you start building your game. But there's plenty of documentation, tutorials, demos and sample projects to point you in the right direction.

The package is now entirely free, too - no annoying limitations, nag screens or anything else. Epic now only requires that you pay a 5% royalty after the first $3,000 of revenue per product per quarter. And even then, you "pay no royalty for film projects, contracting and consulting projects such as architecture, simulation and visualization."

4.15.1 brings:
- Bug Fixes

[...]
Value:
Free
Rating: