How this analysis was created: This summary and feature list are AI-generated from collected project material and can contain mistakes. Stars, license and language are imported from GitHub. Inclusion does not mean that we have tested or audited this project. Check the source documentation for any feature you depend on. Learn more on our About page.
A collection of PowerShell modules designed for artifact gathering and reconnaisance of Windows-based endpoints.
The main features of tonyphipps/meerkat are: Digital Forensics, Windows Evidence Collection.
Projects with overlapping indexed features include: invoke-ir/powerforensics — PowerForensics provides an all in one platform for live disk forensic analysis. ghostpack/seatbelt — Seatbelt is a C# offensive security framework and host security auditor designed to perform endpoint surveys on… ahmedkhlief/apt-hunter — APT-Hunter is Threat Hunting tool for windows event logs which made by purple team mindset to provide detect APT… almco/panorama — Fast incident overview. andrewrathbun/dfirartifactmuseum — DFIR Artifact Museum. ajmartel/irtriage — Incident Response Triage - Windows Evidence Collection for Forensic Analysis.
PowerForensics provides an all in one platform for live disk forensic analysis
Seatbelt is a C# offensive security framework and host security auditor designed to perform endpoint surveys on Windows systems. It functions as a modular tool for identifying vulnerabilities, misconfigurations, and security-relevant artifacts on both local and remote hosts. The project distinguishes itself through a module-based check system that allows for the integration of custom security command units. It features a security event log parser to track logon and process activity, alongside a credential extraction utility for gathering browser history, saved passwords, and cloud credentials
APT-Hunter is Threat Hunting tool for windows event logs which made by purple team mindset to provide detect APT movements hidden in the sea of windows event logs to decrease the time to uncover suspicious activity
Incident Response Triage - Windows Evidence Collection for Forensic Analysis