IRTriage Logo

IRTriage

0
Free
Visit Website

Incident Response Triage is a scripted collection tool that automatically runs as an administrator in Windows versions, except WinXP, to gather system information valuable to a Forensic Analyst. It collects system information, network information, registry hives, disk information, and dumps memory, providing fast forensics in situations where a full disk image is not feasible.

FEATURES

ALTERNATIVES

AMExtractor is an Android Memory Extractor tool.

A command-line tool for extracting detailed information from JPEG files, including image dimensions, compression, and metadata.

A tool with advanced filtering capabilities for analyzing events based on time, path, weekday, and date.

GUI-based memory forensic capture tool for cyber forensics and cyber crime investigation.

Dump iOS Frequent Locations from StateModel#.archive files.

Custom built application for asynchronous forensic data presentation on an Elasticsearch backend, with upcoming features like Docker-based installation and new UI rewrite in React.

A library and set of tools for accessing and analyzing storage media devices and partitions for forensic analysis and investigation.

A forensic tool to find hidden processes and TCP/UDP ports by rootkits or other hidden techniques.

PINNED