PowerForensics Logo

PowerForensics

0
Free
Visit Website

PowerForensics is a PowerShell digital forensics framework for hard drive forensic analysis, supporting NTFS and FAT file systems, with plans for HFS+ and Extended File System support. It provides a public API for forensic tasks, built on a C# Class Library, allowing for modular expansion of capabilities. Documentation and installation instructions can be found on Read The Docs and GitHub.

FEATURES

ALTERNATIVES

A Kernel fuzzer focusing on race bugs

Recreates the File/Directory tree structure from an extracted $MFT file with detailed record mapping and analysis capabilities.

A library to access and parse Windows Shortcut File (LNK) format.

A comprehensive guide to incident response and computer forensics, covering the entire lifecycle of incident response and remediation.

Analyzing WiFiConfigStore.xml file for digital forensics on Android devices.

A Mac OS X forensic utility for ensuring correct forensic procedures during disk imaging.

GUI-based memory forensic capture tool for cyber forensics and cyber crime investigation.

libevt is a library to access and parse Windows Event Log (EVT) files.