PowerForensics Logo

PowerForensics

0
Free
Visit Website

PowerForensics is a PowerShell digital forensics framework for hard drive forensic analysis, supporting NTFS and FAT file systems, with plans for HFS+ and Extended File System support. It provides a public API for forensic tasks, built on a C# Class Library, allowing for modular expansion of capabilities. Documentation and installation instructions can be found on Read The Docs and GitHub.

FEATURES

ALTERNATIVES

A collaborative forensic timeline analysis tool for organizing and analyzing data with rich annotations and comments.

A software that collects forensic artifacts on systems for forensic investigations.

Malscan is a tool to scan process memory for YARA matches and execute Python scripts.

Dump iOS Frequent Locations from StateModel#.archive files.

CyLR is a Live Response Collection tool for quickly and securely collecting forensic artifacts from hosts with NTFS file systems.

A tool for triaging crash files with various output formats and debugging engine options.

A reliable end-to-end DFIR solution for boosting cyber incident response and forensics capacity.

A reverse engineering framework with a focus on usability and code cleanliness

PINNED