Kansa
A modular incident response framework in Powershell that uses Powershell Remoting to collect data for incident response and breach hunts.

Kansa
A modular incident response framework in Powershell that uses Powershell Remoting to collect data for incident response and breach hunts.
Kansa Description
A modular incident response framework in Powershell that uses Powershell Remoting to run user-contributed modules across hosts in an enterprise to collect data for incident response, breach hunts, or building an environmental baseline. It's recommended to upgrade to Powershell v3 or later for optimal performance. For more information, visit: - http://trustedsignal.blogspot.com/search/label/Kansa - http://www.powershellmagazine.com/2014/07/18/kansa-a-powershell-based-incident-response-framework/ To use it, after downloading and unzipping the project, unblock the ps1 files by running: ls -r *.ps1 | Unblock-File. Ensure to check and set your execution policies accordingly.
Kansa FAQ
Common questions about Kansa including features, pricing, alternatives, and user reviews.
Kansa is A modular incident response framework in Powershell that uses Powershell Remoting to collect data for incident response and breach hunts.. It is a Security Operations solution designed to help security teams with Evidence Collection, Memory Forensics.