A Batch script to collect forensic evidence from older Windows systems such as Windows Server 2003
- Download https://github.com/cado-security/Cado-Batch/releases/download/Release/Cado-Batch-Release.zip and extract on the target system
- Run collect.bat as Administrator
- This will then create a file "collected_files.zip" which can be imported into a forensic processing platform such as Cado Response