PSRecon Logo

PSRecon

0
Free
Visit Website

PSRecon is a PowerShell-based incident response and live forensic data acquisition tool that gathers data from a remote Windows host, organizes the data into folders, hashes all extracted data, and sends the data to the security team. It also includes endpoint lockdown functionality, allowing users to disable an active directory account or quarantine the host until IT/Security can respond. The tool provides a detailed report that is self-contained, making it easy to share. It can be integrated with the organization's Active Defense frameworks to automate rapid forensic data acquisition and lock down the endpoint. PSRecon can be run on local or remote hosts, and offers various options for enabling PSRemoting and Unrestricted PowerShell Execution.

FEATURES

ALTERNATIVES

A command-line utility to show and change EXIF information in JPEG files

A Mac OS X forensic utility for ensuring correct forensic procedures during disk imaging.

A console program for file recovery through data carving.

wxHexEditor is a free hex editor / disk editor with various data manipulation operations and visualization functionalities.

A next-generation crawling and spidering framework for extracting data from websites

Highlighter is a FireEye Market app that integrates with FireEye products to provide enhanced cybersecurity capabilities.

Zenduty's platform provides real-time operational health monitoring and incident response orchestration to improve incident response times and build a solid on-call culture.

A forensic research tool for gathering forensic traces on Android and iOS devices, supporting the use of public indicators of compromise.

PINNED