Meerkat Logo

Meerkat

0
Free
Visit Website

Meerkat is a collection of PowerShell modules designed for artifact gathering and reconnaissance of Windows-based endpoints without requiring a pre-deployed agent. Use cases include incident response triage, threat hunting, baseline monitoring, snapshot comparisons, and more. The tool provides a wide range of artifacts such as host information, network adapters, processes, services, files, audit policies, Windows firewall rules, DLLs, local users, ADS, disks, ports, strings, local groups, recycle bin, hotfixes, ARP, handles, scheduled tasks, hosts file, TPM, DNS, environment variables, autoruns, certificates, software, network routes, sessions, Bitlocker, registry, hardware, shares, domain information, defender event logs, drivers, USB history, metadata events related to login failures, user/group management, and more. It also offers ingestion into SIEMs, quick start guides, usage analysis, and troubleshooting tips.

FEATURES

ALTERNATIVES

XMLStarlet offers a suite of command line utilities for manipulating and querying XML documents.

A library to access and parse Windows Shortcut File (LNK) format.

A tool for restoring defocused and blurred images with various deconvolution techniques and fast processing capabilities.

A library to access the Extensible Storage Engine (ESE) Database File (EDB) format used in various Windows applications.

Comprehensive digital forensics and incident response platform for law enforcement, corporate, and academic institutions.

Digital investigation tool for extracting forensic data from computers and managing investigations.

dc3dd is a patch to the GNU dd program, tailored for forensic acquisition with features like hashing and file verification.

A Mac OS X computer forensics tool for analyzing system artifacts, user files, and logs with reputation verification and log aggregation capabilities.