Skip to content

Entry

PowerForensics

Appears in 6 awesome lists

All in one PowerShell-based platform to perform live hard disk forensic analysis.

Open github.cominvoke-ir/powerforensics

Found in these lists

Awesome Cybersecurity Blue Team

Section: Threat hunting · All in one PowerShell-based platform to perform live hard disk forensic analysis.

StaleScore 53

Awesome Cybersecurity Blue Team - CN

Section: 威胁狩猎 · 基于PowerShell,用于实时硬盘取证分析的多合一平台

StaleScore 47

Awesome Incident Response

Section: Windows Evidence Collection · Live disk forensics platform, using PowerShell.

ActiveScore 82

Awesome PowerShell

Section: Security · Popular live disk forensics platform for windows.

ArchivedScore 54

FBI Tools

Section: Power Forensic

StaleScore 51

Forensics Tools

Section: Frameworks · PowerForensics is a framework for live disk forensic analysis

ActiveScore 77

Fibratus

Fibratus is a tool for exploration and tracing of the Windows kernel. It is able to capture the most of the Windows kernel activity - process/thread creation and termination, file system I/O, registry, network activity, DLL loading/unloading and much more. Fibratus has a very simple CLI which…

In 8 listsDetails

GRR Rapid Response

Incident response framework focused on remote live forensics. It consists of a python agent (client) that is installed on target systems, and a python server infrastructure that can manage and talk to the agent. Besides the included Python API client, PowerGRR provides an API client library in…

In 6 listsDetails

rastrea2r

Multi-platform tool for triaging suspected IOCs on many endpoints simultaneously and that integrates with antivirus consoles.

In 4 lists

Redline

Provides host investigative capabilities to users to find signs of malicious activity through memory and file analysis, and the development of a threat assessment profile.

In 4 lists

HELK

All-in-one Free Software threat hunting stack based on Elasticsearch, Logstash, Kafka, and Kibana with various built-in integrations for analytics including Jupyter Notebook.

In 4 lists

CimSweep

A suite of CIM/WMI-based tools that enable the ability to perform incident response and hunting operations remotely across all versions of Windows

In 4 lists

LOKI

Free IR scanner for scanning endpoint with yara rules and other indicators(IOCs).

In 4 lists

PSRecon

PSRecon gathers data from a remote Windows host using PowerShell (v2 or later), organizes the data into folders, hashes all extracted data, hashes PowerShell and various system properties, and sends the data off to the security team. The data can be pushed to a share, sent over email, or retained…

In 3 lists