Stars
6
stars
written in PowerShell
Clear filter
Powershell module that can be used by Blue Teams, Incident Responders and System Administrators to hunt persistences implanted in Windows machines. Official Twitter/X account @PersistSniper. Made w…
$MFT directory tree reconstruction & FILE record info
An easy to use PowerShell script to collect memory and disk forensics for DFIR investigations.
Collect-MemoryDump - Automated Creation of Windows Memory Snapshots for DFIR
PowerShell script utilized to pull several forensic artifacts from a live Win7 and WinXP system without WINRM.