
PowerShell-based incident response toolkit that collects 25+ forensic artifacts (processes, network connections, registry, browser history) and exports CSV for SIEM integration. Supports Defender for Endpoint Live Response.
This repository provides PowerShell-based Incident Response scripts.
The DFIR-Script.ps1 script collects forensic artifacts on Windows devices. Key features include:
These scripts perform specific tasks, such as collecting Windows Security Events, resetting active user sessions, or uploading a folder to Azure Storage Blob. Some scripts use APIs to retrieve or export data, with required permissions described in each script. The scripts are structured for the Incident Response cycle:
| Phase | Description |
|---|---|
| Acquisition | Scripts and tools for acquiring data and evidence during an incident. |
| Analysis | Sripts for analyzing acquired data to identify indicators of compromise and understand the scope of the incident. |
| Containment | Scripts and methods for containing the incident to prevent further damage and spread. |
The DFIR script collects information from multiple sources and structures the output in the current directory in a folder named 'DFIR-hostname-year-month-date'. This folder is zipped at the end, so that folder can be remotely collected. This script can also be used within Defender For Endpoint in a Live Response session (see below). The DFIR script collects the following information when running as normal user:
For the best experience run the script as admin, then the following items will also be collected:
The forensic artifacts are exported as CSV files, allowing responders to ingest them into tools like Sentinel, Splunk, Elastic, or Azure Data Explorer for filtering, aggregation, and visualization.
The folder CSV Results (SIEM Import Data) includes all the CSV files containing the artifacts:
Name
----
ActiveUsers.csv
AutoRun.csv
ConnectedDevices.csv
DefenderExclusions.csv
DNSCache.csv
Drivers.csv
InstalledSoftware.csv
IPConfiguration.csv
LocalUsers.csv
NetworkShares.csv
OfficeConnections.csv
OpenTCPConnections.csv
PowerShellHistory.csv
Processes.csv
RDPSessions.csv
RemotelyOpenedFiles.csv
RunningServices.csv
ScheduledTasks.csv
ScheduledTasksRunInfo.csv
SecurityEvents.csv
ShadowCopy.csv
SMBShares.csv
The script can be executed by running the following command.
.\DFIR-Script.ps1
The script is unsigned, that could result in having to use the -ExecutionPolicy Bypass to run the script.
Powershell.exe -ExecutionPolicy Bypass .\DFIR-Script.ps1
It is possible to use the scripts in combination with the Defender For Endpoint Live Response. Make sure that Live Response is setup (See DOCS). Since my script is unsigned, a setting change must be made to be able to run the script.
There is a blog article available that explains more about how to leverage Custom Script in Live Response: Incident Response Part 3: Leveraging Live Response
To run unsigned scripts live Response:
Execute script:
run DFIR-script.ps1 to start the script. If you want to run the script using parameters, you should run run DFIR-Script.ps1 -parameters "-sw 10"getfile DFIR-DeviceName-yyyy-mm-dd to download the retrieved artifacts to your local machine for analysis.