
Collect-MemoryDump
Automated PowerShell script for forensically sound Windows memory acquisition, including crash/raw dumps, pagefile collection, triage artifacts, and…

Automated PowerShell script for forensically sound Windows memory acquisition, including crash/raw dumps, pagefile collection, triage artifacts, and…

You didn't think I'd go and leave the blue team out, right?

Automates Windows memory forensics and DFIR workflows with MemProcFS: YARA/ClamAV scanning, process anomaly detection, and artifact/log extraction.

A really good DFIR automation for collecting and analyzing evidence designed for cybersecurity professionals.

A PowerShell Module Dedicated to Reverse Engineering

A post-exploitation powershell tool for extracting juicy info from memory.

PowerShell-based incident response toolkit that collects 25+ forensic artifacts (processes, network connections, registry, browser history) and…

An easy to use PowerShell script to collect memory and disk forensics for DFIR investigations.

Offensive token-harvesting utility that searches x64 process memory and TokenBroker cache files for Azure AD/O365 JWT tokens across Office, Edge,…