PSRecon Logo

PSRecon

0
Free
Visit Website

PSRecon is a PowerShell-based incident response and live forensic data acquisition tool that gathers data from a remote Windows host, organizes the data into folders, hashes all extracted data, and sends the data to the security team. It also includes endpoint lockdown functionality, allowing users to disable an active directory account or quarantine the host until IT/Security can respond. The tool provides a detailed report that is self-contained, making it easy to share. It can be integrated with the organization's Active Defense frameworks to automate rapid forensic data acquisition and lock down the endpoint. PSRecon can be run on local or remote hosts, and offers various options for enabling PSRemoting and Unrestricted PowerShell Execution.

FEATURES

ALTERNATIVES

A tool for triaging crash files with various output formats and debugging engine options.

Tool for parsing NTFS journal files, $Logfile, and $MFT.

Documentation project for Digital Forensics Artifact Repository

A tool for parsing and extracting information from the Master File Table of NTFS file systems.

libevt is a library to access and parse Windows Event Log (EVT) files.

Open Source computer forensics platform with modular design for easy automation and scripting.

A script to extract subdomains/emails for a given domain using SSL/TLS certificate dataset on Censys.

A collaborative forensic timeline analysis tool for organizing and analyzing data with rich annotations and comments.

CyberSecTools logoCyberSecTools

Explore the largest curated directory of cybersecurity tools and resources to enhance your security practices. Find the right solution for your domain.

Copyright © 2024 - All rights reserved