How this analysis was created: This summary and feature list are AI-generated from collected project material and can contain mistakes. Stars, license and language are imported from GitHub. Inclusion does not mean that we have tested or audited this project. Check the source documentation for any feature you depend on. Learn more on our About page.
PowerForensics provides an all in one platform for live disk forensic analysis
Velociraptor is a digital forensics and incident response platform, endpoint detection and response system, and visibility tool. It provides a query engine and remote forensic collector used to hunt for indicators of compromise and perform triage across a fleet of hosts. The system is distinguished by its specialized query language for interrogating host state and parsing binary files. It features a notebook environment that combines markdown documentation with executable query cells to standardize investigative workflows and enable collaborative reporting. The platform covers a wide range o
Seatbelt is a C# offensive security framework and host security auditor designed to perform endpoint surveys on Windows systems. It functions as a modular tool for identifying vulnerabilities, misconfigurations, and security-relevant artifacts on both local and remote hosts. The project distinguishes itself through a module-based check system that allows for the integration of custom security command units. It features a security event log parser to track logon and process activity, alongside a credential extraction utility for gathering browser history, saved passwords, and cloud credentials
:rocket: PSRecon gathers data from a remote Windows host using PowerShell (v2 or later), organizes the data into folders, hashes all extracted data, hashes PowerShell and various system properties, and sends the data off to the security team. The data can be pushed to a share, sent over email, or retained locally.
The main features of gfoss/psrecon are: Forensics, Threat Hunting Operations, Windows Evidence Collection.
Projects with overlapping indexed features include: invoke-ir/powerforensics — PowerForensics provides an all in one platform for live disk forensic analysis. ghostpack/seatbelt — Seatbelt is a C# offensive security framework and host security auditor designed to perform endpoint surveys on… velocidex/velociraptor — Velociraptor is a digital forensics and incident response platform, endpoint detection and response system, and… cugu/awesome-forensics. google/grr — GRR is a distributed incident response platform and asynchronous forensic task orchestrator. It functions as a remote… cyb3rward0g/helk — HELK is a containerized security information and event management environment and threat hunting platform. It provides…