
Trawler
PowerShell script helping Incident Responders discover potential adversary persistence mechanisms.

PowerShell script helping Incident Responders discover potential adversary persistence mechanisms.

Automated PowerShell script for forensically sound Windows memory acquisition, including crash/raw dumps, pagefile collection, triage artifacts, and…

An easy to use PowerShell script to collect memory and disk forensics for DFIR investigations.

PowerShell script to scan Windows Event Logs for CVE-2020-1472 indicators (events 5827-5831), export to CSV, and generate Excel pivot tables for…

PowerShell script that automates the WinRE mitigation workflow for CVE-2026-45585, with verification steps and conditional commit to avoid…

A PowerShell script to identify indicators of exploitation of CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-26865

Scans Windows IIS logs for signs of CVE-2025-53770 & CVE-2025-53771

PowerShell-based incident response toolkit that collects 25+ forensic artifacts (processes, network connections, registry, browser history) and…