Some tools:
DOWNLOAD LINKS
LINK1
LINK2
watch_f_d.exe
Tool to capture new files on disc at a given path. First time run will store a snap shot. Second run will only show new or modified files. Search is recursive under the given path (The timeStamp shown in output path is last modified).
Usage: watch_f_d.exe PathToFolder
Let's use an example:
First run with snapShot
data:image/s3,"s3://crabby-images/49636/49636909a161eb3d3ebc794d76f5ebe57b02765c" alt="Screen Shot 2019-04-30 at 10.09.55 PM"
2nd run with newly added files
data:image/s3,"s3://crabby-images/5e70e/5e70ed485483deb0f2ab1bacc0c1975386c50f44" alt="Screen Shot 2019-04-30 at 10.29.41 PM"
You can add multiple directories to the snap shot using the command line. Its not really meant to use for paths like c:\ as that would be a very long search.
watch_aspx.exe
Tool will look for asps files (ONLY) in a given path. This is real-time only i.e. when a file is added or deleted (with asps extension), user should see the notification:
Usage: watch_aspx.exe pathToFolder
data:image/s3,"s3://crabby-images/d16e3/d16e34ff15b66d6ef4152de35c9c4d8eded47598" alt="Screen Shot 2019-04-30 at 11.37.24 PM"
file_search.exe
Tool will run a recursive search in a given path
Usage: file_search.exe pathToFolder flag
flag value could be a or b
a = get file names and md5 // slower
b = file names only // faster
data:image/s3,"s3://crabby-images/eea17/eea17b3dfdce8e0c96d0b154f94f541cf0cf4947" alt="Screen Shot 2019-04-30 at 11.45.18 PM"
Use find to look for specific patterns e.g.
file_search.exe c:\foo b | find "aspx"
watch_iis_process.exe
Tool will watch for IIS process ONLY, in real-time. It will alert if IIS spawns any other process.
Usage: Double click.
data:image/s3,"s3://crabby-images/e0742/e0742f511ac6929a61c3372975a303ad9a45ec45" alt="Screen Shot 2019-05-01 at 12.09.36 AM"
FILE UPLOAD TOOL
Tool will provide client server mechanism to upload file(s) between client and a server:
file_ser_7777.exe
Will start a server on port 7777
NOTE: Create folder called ud
Uploaded files will be saved under ud folder.
file_upload_client.exe
Will upload a file to the server. File(s) MUST be placed in folder called ud
Usage:
file_upload_client.exe fileName remoteIpAddress
fileName is name of the file that MUST be placed in ud folder.
watch_windows_temp.exe
Watch c:\windows\temp folder recursive. Please make sure you have the right permissions
Usage: Double click
Search String
DownloadTool to search for a string in a given path (RECURSIVE). This could be used to search for specific patterns within IISLOGS
Usage:
search_str.exe string pathToFolder
Example:
search_str.exe evilString c:\inetpub\Logs
OTHER TOOLS
LINK 1LINK 2
LINK 3