Bios Password

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Saturday, December 12, 2009

Free Windows GREP tools – I’m Excited!

Posted on 11:17 PM by Unknown

Back in August ‘09, Keydet89 posed the following question in his Windows Incident Response blog post “Goin’ commando”…

Anyway, I think that is would be a great place to start throwing up information, discussion and links to free and open-source tools that folks are using for analyzing various files or formats. This can include general stuff (such as, does anyone have a good, free grep utility for Windows that doesn't use cygwin?)

Harlan then followed that post with a roundup of new free tools and utilities.  He had also previously shared a  number of freely offered blog posts on, well, free utilities that might benefit both the Windows forensic examiner (and sysadmins as well).

  • Free Tools – The most recent “free tools” post over at Windows Incident Response blog. (10/23/09)
  • Getting started, or forensic analysis on the cheap - Windows Incident Response blog. (02/20/08)
  • Free Analysis - Windows Incident Response blog. (04/20/08)
  • More Free Tools - Windows Incident Response blog. (05/25/09)

Anyway…I think his was a rhetorical question regarding the Windows grep utility, but I responded in the comments about my own personal freeware grep favorite…

  • BareGrep - Free grep for Windows – Bare Metal Software.  Great tool for advanced and complex system and file searching for only 246 kB in size but very fast and very advanced for the most demanding system-inspecting needs.  Simply amazing.  Oh yes. It’s a single non-installing exe file and fully portable. Works great on XP through Windows 7 systems.  I’ve used it with great success to narrow my analysis on a few incident response assignments.  It really saved the day.

Since then I have found and collected a few more freeware grep tools. Most are GUI-based but a few are command-line.  Take your pick.

  • File Hound 3.08 - (freeware) – JimmyTheFork.com.  An updated version of his “Hound” grep tool.  I spotted it mentioned over in this DonationCoder thread Hound: a grep-alike that searches inside PDFs.  For a sample of the GUI see this Hound screenshot link.  Fully portable, download, unzip and run the exe.  I particularly like the fact that it is more intuitive to use and identify the result locations than the uber-powerful BareGrep utility.
  • Windows Grep - (freeware) – brilliant app which ran great “portably” on my Windows 7 system.  The GUI interface is very pleasant and modern (in a no-frills way).  What stood out the strongest to me was the interactive “wizard” that runs first. It nicely guides n00bies through the basic steps of setting up a search pattern, a location, and other parameters before kicking off the search.  Don’t be fooled. It’s got some advanced searching power for the experts to tap as well. The results are wonderfully displayed in an index format and the preview pane below highlights all the findings for very fast analysis.  Good job Huw Millington! Most excellent tool.
  • PRGrep - (freeware) – Another surprisingly well crafted GUI-based grep tool for Windows. Again, it seems to be portable.  Not quite as user-friendly for the uninitiated, anyone who does grep work will pick its functions up quickly.  Searching was fast and like Windows Grep, the display hits are nicely detailed and highlighted in the lower pane.  It can plug into MS Office for Word/Excel file reading.  I particularly liked the “old-school” format which makes copy/paste activity a breeze. PRGrep documentation is outstanding.
  • GREP for Windows - A very flexible grep for windows – (freeware) - opbarns.com O. Patrick Barns did an 2006 update to Tim Charron’s "GREP for Windows" port. He cleaned up some bugs in that version as seem to relate to subdirectory searching with the "-S” argument.  Yep.  CLI only with this one, baby.
  • Grep for Windows and GREP for Windows both of which seem to be the original CLI ports by Tim Charron of the GNU grep 2.0 allowing for sub-directory searching.  Examples of syntax provided on the pages.
  • GREP Command for Windows XP - Windows XP and DOS – Malektips.com – Tips to use of QGREP command.  Note: it does require extraction from Windows 2003 Resource Kit.  Syntax and expression usage documented there wonderfully as well.  More info on the Win2003RK here.  I’m guessing that if it works on XP, it should do OK on Vista and Windows 7 as well.

Curious News on Future Windows Resource Kits

Note that according to information and references in this Resource Kit – Wikipedia article…

In 2007 and 2008 respectively, Microsoft released the Windows Vista and Windows Server 2008 Resource Kits. Microsoft has also released resource kits for Group Policy, Windows security, Active Directory, Terminal Services and IIS 7. The Windows Vista Resource Kit ships with several sample VBScripts and few PowerShell scripts.

The Windows 7 Resource Kit was released on 14 September 2009 [3]. Microsoft has announced that new unsupported resource kit tools will not be provided for current and future operating systems [4], however the PowerShell team has released a Resource Kit PowerShell Pack [5], a collection of PowerShell modules that adds over 700 scripts to those already present in Windows 7.

References

[3]  Windows 7 Resource Kit: Microsoft Press blog

[4]  Are Resource Kits Dead? NOPE!

[5]  Introducing the Windows 7 Resource Kit PowerShell Pack

To be clear; the Resource Kits are alive and well, but it looks like the traditional “unsupported” tools and utilities that came with them, beloved by sysadmins world-wide, are now an endangered species.

See how it works?

Ask a question, get a slew of cool free utilities for the sysadmin and forensic pros alike!

Cheers!

--Claus V.

Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Posted in command-line interface, forensics, Microsoft, utilities, Vista, Windows 7, XP | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • Finally! Time to Post! New material list
    After a recent text from my bro reminding me it has been since March since I’ve done a blog post, I was finally able to clear the schedule a...
  • Oscar watch Linkpost
    Alvis and Lavie are watching the Oscars tonight and I’m along for the ride. I wasn’t able to come even close to getting out some of the pos...
  • New Year’s Day - First Post 2011
    Same day I came out with my first post after a long drought, I fell upon this article Blogging Seems To Have Peaked, Says Pew Report over a...
  • Utility Gumbo
    There’s a lot in this pot.  Probably something everyone can find to enjoy. I’m serving it up tonight out of the back of the truck on the s...
  • iodd : Multi-boot madness!
    Like many computer technicians and responders, I seem to always have at hand a collection of bootable media; CD’s, DVD’s, USB-HDD’s, flash m...
  • Ubuntu 13.10 Upgrade - Lessons Learned & VIDMA utility found
    A few weeks ago a new release of Ubuntu came out. Naturally that meant it was update time! I have been getting pretty good at this now so ...
  • Interesting Malware in Email Attempt - URL Scanner Links
    Last weekend I spent some time with extended family helping confirm for them that their on-line email account got hacked and had been used t...
  • Windows 8 Linkage: A Bit Behind the Ball
    CC attribution: behind the eight ball by Ed Schipul on flickr . OK. Confession time. I’m more than a bit exhausted this weekend. Besides a...
  • Lego MiniFig Extravaganza
    picture clipped from Wired’s clip from Gizmodo clip… Thanks in no small part to the Windows 7 RC release, XPM mode research, and a big “l...
  • This Week in Security and Forensics: Beware the cake!
    Cube Party! image used with permission from John Walker at "rockpapershotgun.com" Yeah, the cake is a Portal thing.  Let’s d...

Categories

  • Active Directory
  • anti-virus software
  • Apple
  • architecture
  • art
  • AVG
  • Blogger
  • blogging
  • books
  • boot-cd's
  • browsers
  • cars
  • cell-phones
  • cheat sheets
  • Chrome/Chromium
  • command-line interface
  • cooking
  • crafts
  • crazy
  • curmudgeon
  • DHC
  • Dr. Who
  • E-P1
  • Education
  • family
  • Firefox
  • firewalls
  • For the Gentleman
  • forensics
  • Gmail
  • Google
  • graphics
  • hacks
  • hardware
  • humor
  • hurricanes
  • imagex
  • Internet Explorer
  • iOS
  • iPhone
  • iPod
  • iTunes
  • Kindle
  • Learning
  • Link Fest
  • Linux
  • malware tools
  • Microsoft
  • movies
  • music
  • networking
  • NewsFox
  • NFAT
  • Nook
  • Opera
  • organization
  • PDF's
  • photography
  • politics
  • PowerShell
  • recipes
  • Remote Support
  • RSS
  • science
  • Scripting
  • search engines
  • security
  • Shuttle SFF
  • software
  • Texana
  • Thunderbird
  • troubleshooting
  • TrueCrypt
  • tutorials
  • utilities
  • VBscript
  • video
  • Virtual PC
  • virtualization
  • viruses
  • Vista
  • Vista mods
  • wallpapers
  • Win FE
  • Win PE
  • Win RE
  • Windows 7
  • Windows 8
  • Windows Home Server
  • Windows Live Writer
  • Windows Phone
  • writing
  • XP
  • XP mods
  • Xplico

Blog Archive

  • ►  2013 (83)
    • ►  November (8)
    • ►  October (8)
    • ►  September (14)
    • ►  August (6)
    • ►  July (10)
    • ►  June (10)
    • ►  April (11)
    • ►  March (6)
    • ►  February (7)
    • ►  January (3)
  • ►  2012 (96)
    • ►  December (8)
    • ►  November (4)
    • ►  October (9)
    • ►  September (8)
    • ►  August (12)
    • ►  July (4)
    • ►  June (3)
    • ►  May (7)
    • ►  April (13)
    • ►  March (3)
    • ►  February (5)
    • ►  January (20)
  • ►  2011 (41)
    • ►  December (8)
    • ►  November (7)
    • ►  September (4)
    • ►  August (4)
    • ►  July (2)
    • ►  June (6)
    • ►  March (5)
    • ►  February (1)
    • ►  January (4)
  • ►  2010 (69)
    • ►  December (1)
    • ►  October (3)
    • ►  September (2)
    • ►  August (13)
    • ►  July (17)
    • ►  June (3)
    • ►  May (3)
    • ►  April (3)
    • ►  March (11)
    • ►  February (1)
    • ►  January (12)
  • ▼  2009 (177)
    • ▼  December (20)
      • Browser Wars
      • iTunes Damage Control
      • Tiny CLI Revisit
      • T-Bird 3.0 versus Outlook 2010 (beta)
      • Run Windows Remote Desktop Connection on Win7 “Hom...
      • I’m no dummy (but I know how to make one…)
      • Tiny Stuff
      • For the Geeky Crew _ Mostly Virtualized
      • DECAF and COFEE, and a brush
      • Mostly Windows Virtualization stuff
      • Sync & Backup Tools (freeware)
      • Get your Big Whata-Microsoft Linkdump Here!
      • Minor manual tweaking of freeCommander
      • Hmmm. So that '403-thing' WAS a real problem...
      • Free Windows GREP tools – I’m Excited!
      • Brief Adobe Update News
      • In Texas? Really!
      • Get Yer Own Free DNS Service!
      • Valca Mobile Phone Upgrade
      • More to come…but for now…drive recovery first
    • ►  November (11)
    • ►  October (7)
    • ►  September (7)
    • ►  August (21)
    • ►  July (17)
    • ►  June (7)
    • ►  May (18)
    • ►  April (9)
    • ►  March (17)
    • ►  February (23)
    • ►  January (20)
  • ►  2008 (35)
    • ►  December (23)
    • ►  November (12)
Powered by Blogger.

About Me

Unknown
View my complete profile