Meerkat is a collection of PowerShell modules designed for artifact gathering and reconnaissance of Windows-based endpoints without requiring a pre-deployed agent. Use cases include incident response triage, threat hunting, baseline monitoring, snapshot comparisons, and more. The tool provides a wide range of artifacts such as host information, network adapters, processes, services, files, audit policies, Windows firewall rules, DLLs, local users, ADS, disks, ports, strings, local groups, recycle bin, hotfixes, ARP, handles, scheduled tasks, hosts file, TPM, DNS, environment variables, autoruns, certificates, software, network routes, sessions, Bitlocker, registry, hardware, shares, domain information, defender event logs, drivers, USB history, metadata events related to login failures, user/group management, and more. It also offers ingestion into SIEMs, quick start guides, usage analysis, and troubleshooting tips.
This tool is not verified yet and doesn't have listed features.
Did you submit the verified tool? Sign in to add features.
Are you the author? Claim the tool by clicking the icon above. After claiming, you can add features.
A library to access the Extensible Storage Engine (ESE) Database File (EDB) format used in various Windows applications.
A tool that uses graph theory to reveal hidden relationships and attack paths in an Active Directory environment.
Web interface for the Volatility Memory Analysis framework with advanced features.
A script to assist in creating templates for VirtualBox to enhance VM detection evasion.
NBD is a userland implementation of the Network Block Device protocol, allowing for remote access to block devices over a network.
Automated digital image forensics tool