Live Response Collection
windows-live-response.bat
Collects live triage data from a Windows host with Live Response Collection, packaging system artifacts.
Run it when you need ready-to-use live triage collection: Live Response Collection (from Brimor Labs) runs its collection battery — system information, processes, connections, services, registry, recent files — and packages the results into a zip with an organized structure. It's the simple triage collector: run the .bat, take the zip. In IR, Live Response Collection is the quick option for host triage: system data in one file, no prior configuration.
Don't use it as a complete forensic collection: the collection covers triage data (processes, network, services, registry) — deep artifacts (MFT, full prefetch, raw EVTX) require KAPE or CyLR. Running on the compromised host alters data (commands touch the system): IR order is respected. And watch out: the .bat runs with the console — on hosts without permissions, collection is partial; and the project is barely maintained (the current alternative is KAPE/CyLR). For triage with standardized artifacts, KAPE; Live Response Collection is the historical and simple option for point-in-time triage.