PowerForensics

Forensic analyzer

A C#-based framework for analyzing and investigating hard drive forensic data

PowerForensics provides an all in one platform for live disk forensic analysis

GitHub

1k stars
158 watching
274 forks
Language: C#
last commit: almost 3 years ago
Linked from 4 awesome lists


Backlinks from these awesome lists:

Related projects:

RepositoryDescriptionStars
invoke-ir/forensicpostersA tool for creating and analyzing digital poster forensics data437
swisscom/invoke-forensicsTools for automating forensic analysis with KAPE and RegRipper109
securityjoes/forensicminerAutomates evidence collection and analysis from Windows machines using PowerShell.149
invoke-ir/aceA suite of tools for automating data collection and enrichment across multiple operating systems.322
microsoft/infersharpA tool that analyzes C# code for potential issues such as null pointer dereferences and resource leaks to help detect security vulnerabilities.737
jimtin/ircoreforensicframeworkAutomates incident response actions to gather and process forensic artefacts from remote systems22
flo354/iosforensicA tool to aid in forensic analysis of iOS devices63
mgreen27/invoke-liveresponseA live response tool for targeted collection of data from compromised devices.145
anssi-fr/dfir4vsphereA PowerShell module for collecting logs and forensics data from VMware vSphere environments.143
thehive-project/cortex-analyzersDevelops and stores Cortex analyzers & responders for incident response and threat intelligence.437
vitaly-kamluk/bitscoutA customizable tool for creating bootable disk images for remote system analysis and forensic investigations.464
pjrinaldi/wombatforensicsA multi-threaded GUI forensic analysis tool for Linux48
dissectmalware/officeforensictoolsA Python-based collection of tools for gathering forensic information from Office documents26
evild3ad/memprocfs-analyzerAutomated tool for forensic analysis of Windows memory dumps555
shanek2/invtero.netAnalyzes and validates physical memory from various systems to extract process information and hypervisor details281