logo

Literature Survey On Windows Incident Response Tool

Authors

  • Shahina K.K

    ViswaJyothi College of Engineering and Technology Ernakulam, Kerala
    Author
  • Abia Paul

    ViswaJyothi College of Engineering and Technology Ernakulam, Kerala
    Author
  • Adole Saju

    ViswaJyothi College of Engineering and Technology Ernakulam, Kerala
    Author
  • Hemil Antony

    ViswaJyothi College of Engineering and Technology Ernakulam, Kerala
    Author
  • Sherin Paulose

    ViswaJyothi College of Engineering and Technology Ernakulam, Kerala
    Author

Abstract

Incident response is a systematic process used by organizations to manage data breaches and cyberattacks, with the
goal of minimizing damage, reducing recovery time, and preserving operational continuity. This work presents a Windows Incident
Response Tool designed to enhance and accelerate investigation procedures within Windows environments by utilizing the Windows
Remote Management (WinRM) service. The tool automates the collection of critical forensic artifacts—including network
configuration, user accounts, scheduled tasks, registry entries, firewall rules, running services, active ports, file shares, system files,
event logs, and active sessions—providing a centralized and structured dataset for analysis. By consolidating this information,
security analysts can more easily detect anomalies, identify indicators of compromise, and make informed response decisions.
Automation through WinRM reduces manual effort, improves consistency in evidence gathering, and streamlines the overall
incident response workflow. The proposed system aims to support faster identification, analysis, and remediation of security incidents,
thereby improving the effectiveness and efficiency of Windows based digital forensics and incident response operations.

Keywords:

Windows Incident Response Tool (WIRT), Windows Remote Management (WinRM), Digital Forensics, Cybersecurity Incident Response, Automated Data Collection
Views 0
Downloads 0

Published

29-05-2026

Issue

Section

Articles

How to Cite

[1]
S. K.K, A. Paul, A. Saju, H. Antony, and S. Paulose, “Literature Survey On Windows Incident Response Tool”, IJERA, vol. 6, no. 1, pp. 9–12, May 2026, Accessed: May 29, 2026. [Online]. Available: https://ijera.in/index.php/IJERA/article/view/325

Similar Articles

11-20 of 213

You may also start an advanced similarity search for this article.