How this analysis was created: This summary and feature list are AI-generated from collected project material and can contain mistakes. Stars, license and language are imported from GitHub. Inclusion does not mean that we have tested or audited this project. Check the source documentation for any feature you depend on. Learn more on our About page.
Incident Response Triage - Windows Evidence Collection for Forensic Analysis
The main features of ajmartel/irtriage are: Windows Evidence Collection.
Projects with overlapping indexed features include: ghostpack/seatbelt — Seatbelt is a C# offensive security framework and host security auditor designed to perform endpoint surveys on… gfoss/psrecon — :rocket: PSRecon gathers data from a remote Windows host using PowerShell (v2 or later), organizes the data into… invoke-ir/powerforensics — PowerForensics provides an all in one platform for live disk forensic analysis. keydet89/regripper3.0 — RegRipper3.0. mgreen27/invoke-liveresponse — Invoke-LiveResponse. omenscan/achoir — Windows Live Artifacts Acquisition Script.
Seatbelt is a C# offensive security framework and host security auditor designed to perform endpoint surveys on Windows systems. It functions as a modular tool for identifying vulnerabilities, misconfigurations, and security-relevant artifacts on both local and remote hosts. The project distinguishes itself through a module-based check system that allows for the integration of custom security command units. It features a security event log parser to track logon and process activity, alongside a credential extraction utility for gathering browser history, saved passwords, and cloud credentials
:rocket: PSRecon gathers data from a remote Windows host using PowerShell (v2 or later), organizes the data into folders, hashes all extracted data, hashes PowerShell and various system properties, and sends the data off to the security team. The data can be pushed to a share, sent over email, or retained locally.
PowerForensics provides an all in one platform for live disk forensic analysis