
An easy to use PowerShell script to collect memory and disk forensics for DFIR investigations.
Collection profiles include:
CyberPipe supports saving output directly to a network share using the -Net parameter. Simply specify the UNC path (e.g., \\server\share) and the script will automatically map the network drive and perform the collection. This is ideal for automated DFIR workflows triggered by EDR or SOC alerts.
.\CyberPipe.ps1 -Net "\\server\share"
$process.ExitCode not reliably populated after WaitForExit()Run full triage (default collection profile) to local USB drive: (RAM, Pagefile, Volatile, System Files)
.\CyberPipe.ps1
Run RAM & Operating System Files (triage light) capture:
.\CyberPipe.ps1 -CollectionProfile RAMSystem
Run memory-only capture:
.\CyberPipe.ps1 -CollectionProfile RAMOnly
Run RAM & Pagefile capture:
.\CyberPipe.ps1 -CollectionProfile RAMPage
Run RAM & Operating System Files (triage light) capture:
.\CyberPipe.ps1 -CollectionProfile RAMSystem
Run volatile-only capture:
.\CyberPipe.ps1 -CollectionProfile Volatile
Run quick triage (fast collection):
.\CyberPipe.ps1 -CollectionProfile QuickTriage
Run full triage with compression:
.\CyberPipe.ps1 -Compress
Run collection to network share:
.\CyberPipe.ps1 -Net "\\server\share"
Run network collection with specific profile:
.\CyberPipe.ps1 -Net "\\server\share" -CollectionProfile QuickTriage
Run network collection with compression:
.\CyberPipe.ps1 -Net "\\server\share" -Compress
You can modify or create custom profiles by specifying CLI arguments supported by MAGNET Response.
USB Collections: The Tools directory should be located alongside the script:
E:\Triage\CyberPipe\CyberPipe.ps1
E:\Triage\CyberPipe\Tools\
Network Collections: The Tools directory should be placed in the root of the network share:
\\Server\share\Tools\
If you previously used CyberPipe with KAPE (prior to v5), the older workflow remains available in CyberPipe.v4.01.ps1.
Note: CyberPipe was previously known as CSIRT-Collect. The project was renamed starting with version 4.0.
For more information visit Baker Street Forensics