Windows
 
Mac
 
Linux
 
iPhone
 
iPad
 
Android

RSS Feeds

Receive a regular RSS feed from our latest, most popular and recommended downloads

Latest downloads feed

Get a regular RSS from our most latest downloads

Most popular downloads feed

Get a regular RSS from our most popular downloads

Recommended downloads feed

Get a regular RSS from our recommended downloads

Newsletter

Subscribe to either one of our two newsletters for regular updates and information

Downloads newsletter

This is a weekly newsletter with download news, updates and other information

This is a monthly newsletter with software store information, offers and deals

AChoir 0.96a

Collect detailed forensic data on any PC

by Mike Williams

Our Rating:
Your Rating:
Login to rate
Based on 0 ratings
License: Open Source
Operating Systems: Windows 10, Windows 7 (32 bit), Windows 7 (64 bit), Windows 8
Requirements:
Languages: English
Software Cost: Free
Date Updated: 15 April 2017
Watchlist: Add download to my watchlist
Downloads To Date: 523
Developer: OMENScan
RSS News Feed:
Back up your data with Acronis True Image 2016 with a 1-PC LIFETIME license, only $34.99, saving 50%, from store.pcauthority.com.au
AChoir
Collect detailed forensic data on any PC

AChoir is a scriptable open-source tool which enables collecting a host of forensic data on a target PC.

The details include basic system and hardware information, installed applications, drivers, user groups and accounts, network adapters, running processes (copies of the executables, not just the names), currently open network connections, browsing history, and raw data including dumps of RAM, NTFS data (MFT, UsnJrnl etc), event logs, Registry hives and more.

AChoir assembles most of this information with the help of other free or open-source tools, including AutoRuns to find your startup programs, and NirSoft's LastActivityView to build a timeline of the user's recent actions.

You don't need to have any of these tools in advance, AChoir doesn't break any license by bundling programs itself. Instead, when you first run AChoir-inst.exe, the program automatically downloads everything it needs. (The "Install" just collects all the files you need in a single folder tree. Make this a USB key and you've created a portable toolkit you can run anywhere.)

When you're ready, running AChoir.exe or AChoir64.exe in the installation folder will start the data collection process. This takes a while, and requires a lot of space, mostly due to the complete RAM dump. HTML reports and copies of the various data files are stored in a local folder.

This all ran smoothly when we tried it, but the key point of AChoir is that it's all controlled via custom scripts. Here's a very small part from the default file:

SAY: 10. Gathering Running Process List Information...
SAY:
SYS:Tasklist /v > &Acq\Tasklist.dat
SYS:Tasklist /M > &Acq\TaskAll.dat
SYS:\SYS\PSList.exe /accepteula -x > &Acq\PSList.dat

The "SAY" and "SYS" commands are displaying prompts or running actions, and everything else is essentially just a batch file. AChoir is using the built-in TaskList command to record details of running tasks, SysInternals' PsList to capture more, and redirecting the output of both to a report file.

This makes it extremely easy to reconfigure the program. Don't need the full memory dump? Delete those lines. Want to use some other NirSoft tool, instead? Find the command line switches you need and add it to the script.

* AChoir v0.55 - Add LST: - Looping Object (&LST) that reads entries from a file. Also Add SID (file owner) copy on the CPY: command.

Verdict:

AChoir isn't for beginners, but if you need to collect a lot of data on a PC then it's a solid and configurable way to start.

Your Comments & Opinion
 
Related Download Articles
 
JPEGSnoop

JPEGSnoop 1.8.0

Open Source

Has a JPEG image been edited? Here's one way to find out (maybe)

Shutdown Logger

Shutdown Logger 1.0

Freeware

Who's booted your PC, and when?

WinPrefetchView (64-bit)

WinPrefetchView 1.35 (64-bit)

Freeware

Troubleshoot program startup problems

WinPrefetchView (32-bit)

WinPrefetchView 1.35

Freeware

Troubleshoot program startup problems

Other Download Articles From This Category
Ghostery for Firefox

Ghostery for Firefox 7.3.1

Freeware

Discover the web sites that track you and then take back control

ESET Internet Security 10

ESET Internet Security 10.1.219

Trial Software

Protect your PC from hackers, malware and more

ESET Smart Security Premium 10

ESET Smart Security Premium 10.1.219.0

Trial Software

Sample ESET's latest innovations with this powerful security suite

McAfee Avert Stinger (64-bit)

McAfee Avert Stinger 12.1.0.2441 (64-bit)

Freeware

Seek out and destroy the most common malware with a click

PC & Tech Authority Software News

Please wait while my feed loads

See more posts...

Our Price: $19.95
RRP: $49.99
Saving 60%
Buy Now
Offer Ends In:
 

Spotlight: Free Full Software

WhatsApp Messenger 2.17.41

Free Full Commercial Software

WhatsApp Messenger is the world's most popular instant messaging app for smartphones.

You can use it to send and receive text and voice messages, photos, videos, even call your friends in other countries, and because it uses your phone's internet connection it might not cost you anything at all (depending on whether you'll pay data charges).

It's easy to set up and use. There's no need to create and remember new account names or pins because it works with your phone number, and uses your regular address book to find and connect you with friends who use WhatsApp already.

You can talk one-to-one or in group chats, and because you're always logged in there's no way to miss messages. Even if your phone is turned off, WhatsApp will save your messages and display them as soon as you're back online.

There's plenty more (location sharing, contact exchange, message broadcasting) and the app is free for a year, currently $0.99/ year afterwards.

What's New in Version 2.17.41

• Pin chats to the top of your chat list, so you can quickly find them. Just swipe right on a chat and tap the pin icon.
• You can now send documents of any type. To send a document, open a chat, tap attach — document. 
• When you receive multiple photos, you can now tap and hold on the group of photos to quickly forward or delete all of them.

[...]
Value:
Free
Rating: