New artifact (module) templates for the LEAPP family of triage tools.
Artifacts parsing scripts can be found in the the scripts->artifacts folder of LEAPP tools.
General procedure for creating a new artifact (module) is:
- Copy this template into the scripts -> artifacts folder.
- Rename the template to the artifact name. No duplicates allowed.
- Edit scripts -> ilap_artifacts.py, and add your artfiact information and target files.
- Edit the new template file to include your artifact parser and adjust reporting.