awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
Back to gfoss/psrecon

Projects sharing features with PSRecon

19 open-source projects similar to gfoss/psrecon, ranked by shared indexed features. Tags may describe platforms or build tools rather than the same primary purpose. Check each project’s use case, license, and deployment requirements before treating it as a replacement.

  • invoke-ir/powerforensicsInvoke-IR avatar

    Invoke-IR/PowerForensics

    1,435View on GitHub↗

    PowerForensics provides an all in one platform for live disk forensic analysis

    C#
    View on GitHub↗1,435
  • ghostpack/seatbeltGhostPack avatar

    GhostPack/Seatbelt

    4,619View on GitHub↗

    Seatbelt is a C# offensive security framework and host security auditor designed to perform endpoint surveys on Windows systems. It functions as a modular tool for identifying vulnerabilities, misconfigurations, and security-relevant artifacts on both local and remote hosts. The project distinguishes itself through a module-based check system that allows for the integration of custom security command units. It features a security event log parser to track logon and process activity, alongside a credential extraction utility for gathering browser history, saved passwords, and cloud credentials

    C#
    View on GitHub↗4,619
  • velocidex/velociraptorVelocidex avatar

    Velocidex/velociraptor

    3,769View on GitHub↗

    Velociraptor is a digital forensics and incident response platform, endpoint detection and response system, and visibility tool. It provides a query engine and remote forensic collector used to hunt for indicators of compromise and perform triage across a fleet of hosts. The system is distinguished by its specialized query language for interrogating host state and parsing binary files. It features a notebook environment that combines markdown documentation with executable query cells to standardize investigative workflows and enable collaborative reporting. The platform covers a wide range o

    Godigital-forensicsendpoint-discoveryendpoint-protection
    View on GitHub↗3,769
  • cyb3rward0g/helkCyb3rWard0g avatar

    Cyb3rWard0g/HELK

    3,926View on GitHub↗

    HELK is a containerized security information and event management environment and threat hunting platform. It provides a security-focused deployment of the ELK stack, combining Elasticsearch, Logstash, and Kibana into a specialized platform for investigating logs and discovering hidden patterns in network and system security data. The project functions as a security data science suite, integrating interactive computational notebooks and distributed processing tools to run machine learning and graph analytics on security logs. This allows for the identification of hidden attack patterns and an

    Jupyter Notebook
    View on GitHub↗3,926

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Find more with AI search
  • google/grrgoogle avatar

    google/grr

    5,074View on GitHub↗

    GRR is a distributed incident response platform and asynchronous forensic task orchestrator. It functions as a remote forensics framework designed to collect and analyze volatile data, system memory, and digital artifacts from remote hosts during security incident response. The system operates as a remote endpoint triage system, utilizing a coordinated architecture to manage a fleet of agents. It enables the execution of investigative tasks across multiple systems, allowing for the search of files and registries across a large fleet of machines to identify compromised hosts. The platform pro

    Python
    View on GitHub↗5,074
  • infocyte/pshuntInfocyte avatar

    Infocyte/PSHunt

    291View on GitHub↗

    Powershell Threat Hunting Module

    PowerShell
    View on GitHub↗291
  • keydet89/regripper3.0keydet89 avatar

    keydet89/RegRipper3.0

    704View on GitHub↗

    RegRipper3.0

    Perl
    View on GitHub↗704
  • ajmartel/irtriageAJMartel avatar

    AJMartel/IRTriage

    139View on GitHub↗

    Incident Response Triage - Windows Evidence Collection for Forensic Analysis

    AutoIt
    View on GitHub↗139
  • mozilla/mozdefmozilla avatar

    mozilla/MozDef

    2,164View on GitHub↗

    DEPRECATED - MozDef: Mozilla Enterprise Defense Platform

    Python
    View on GitHub↗2,164
  • msuhanov/linux-write-blockerM

    msuhanov/Linux-write-blocker

    0View on GitHub↗
    View on GitHub↗0
  • neo23x0/lokiNeo23x0 avatar

    Neo23x0/Loki

    3,763View on GitHub↗

    Loki is an endpoint detection tool, forensic artifact analyzer, and threat intelligence scanner. It functions as a YARA-based indicator of compromise scanner designed to identify malicious persistence mechanisms, web shells, and unauthorized administration tools across local and remote systems. The project distinguishes itself by integrating multi-source threat intelligence, allowing for the loading of custom signature sets and encrypted indicators. It combines hash-based artifact detection with YARA rule execution to scan files, process memory, and registry hives for known malicious byte seq

    Python
    View on GitHub↗3,763
  • omenscan/achoirOMENScan avatar

    OMENScan/AChoir

    192View on GitHub↗

    Windows Live Artifacts Acquisition Script

    C++
    View on GitHub↗192
  • powershellmafia/cimsweepPowerShellMafia avatar

    PowerShellMafia/CimSweep

    658View on GitHub↗

    CimSweep is a suite of CIM/WMI-based tools that enable the ability to perform incident response and hunting operations remotely across all versions of Windows.

    PowerShell
    View on GitHub↗658
  • rabbitstack/fibratusrabbitstack avatar

    rabbitstack/fibratus

    2,493View on GitHub↗

    Adversary tradecraft detection, protection, and hunting

    Goadversaryblueteamedr
    View on GitHub↗2,493
  • rastrea2r/rastrea2rrastrea2r avatar

    rastrea2r/rastrea2r

    242View on GitHub↗

    Collecting & Hunting for IOCs with gusto and style

    Python
    View on GitHub↗242
  • tonyphipps/meerkatTonyPhipps avatar

    TonyPhipps/Meerkat

    483View on GitHub↗

    A collection of PowerShell modules designed for artifact gathering and reconnaisance of Windows-based endpoints.

    PowerShell
    View on GitHub↗483
  • mgreen27/invoke-liveresponsemgreen27 avatar

    mgreen27/Invoke-LiveResponse

    152View on GitHub↗

    Invoke-LiveResponse

    PowerShell
    View on GitHub↗152
  • almco/panoramaAlmCo avatar

    AlmCo/Panorama

    41View on GitHub↗

    Fast incident overview

    Python
    View on GitHub↗41
  • cugu/awesome-forensicscugu avatar

    cugu/awesome-forensics

    4,911View on GitHub↗
    computer-forensicsdfirdigital-forensics
    View on GitHub↗4,911