
ForensicMiner
A really good DFIR automation for collecting and analyzing evidence designed for cybersecurity professionals.
digital-forensicsdisk-forensicsforensics+2
164

A really good DFIR automation for collecting and analyzing evidence designed for cybersecurity professionals.

Automated PowerShell script for forensically sound Windows memory acquisition, including crash/raw dumps, pagefile collection, triage artifacts, and…

A PowerShell Module Dedicated to Reverse Engineering

A post-exploitation powershell tool for extracting juicy info from memory.

Automates Windows memory forensics and DFIR workflows with MemProcFS: YARA/ClamAV scanning, process anomaly detection, and artifact/log extraction.