PowerForensics Logo

PowerForensics

0
Free
Visit Website

PowerForensics is a PowerShell digital forensics framework for hard drive forensic analysis, supporting NTFS and FAT file systems, with plans for HFS+ and Extended File System support. It provides a public API for forensic tasks, built on a C# Class Library, allowing for modular expansion of capabilities. Documentation and installation instructions can be found on Read The Docs and GitHub.

FEATURES

ALTERNATIVES

A collection of Mac OS X and iOS forensics resources with a focus on artifact collection and collaboration.

A reconnaissance tool for GitHub organizations

Open source tool for generating YARA rules about installed software from a running OS.

TestDisk is a free data recovery software that can recover lost partitions and undelete files from various file systems.

Analyse a forensic target to find and report files found and not found in hashlookup CIRCL public service.

Rekall is a discontinued project that aimed to improve memory analysis methodology but faced challenges due to the nature of in-memory structure and increasing security measures.

Python tool for remote memory acquisition

A PowerShell-based incident response and live forensic data acquisition tool for Windows hosts.

PINNED