- ποΈ Dumps all packages, services, processes (running), applications (installed in .MSI format).
- π Prompts user to open the dump location, for analysis/learning.
- π Can be used to send logs to a backup location or forensics.
- cd To_Extracted/PS_Dump
- Set-ExecutionPolicy Unrestricted
- Yes > to this script/prompt ONLY
- When running the script is allowed, type in (while being in the PS_Dump directory):
.\PS_Dump.ps1
- Follow the on-screen instructions.
If the error with the Red X pops, it means that the shared installed .MSIs will not be included in the log.
(Your firewall may be blocking a call to Microsoft servers, or you may be offline, no worries.)