ForensicMiner

Evidence collector

Automates evidence collection and analysis from Windows machines using PowerShell.

A really good DFIR automation for collecting and analyzing evidence designed for cybersecurity professionals.

GitHub

149 stars
6 watching
19 forks
Language: PowerShell
last commit: 8 months ago
Linked from 1 awesome list

automationcortexcrowdstrikecyberdfiredrfastforensicsirmdrpowershellsecuritysocxdr

Backlinks from these awesome lists:

Related projects:

Repository Description Stars
invoke-ir/powerforensics A C#-based framework for analyzing and investigating hard drive forensic data 1,389
evild3ad/memprocfs-analyzer Automated tool for forensic analysis of Windows memory dumps 555
anssi-fr/dfir4vsphere A PowerShell module for collecting logs and forensics data from VMware vSphere environments. 143
google/turbinia Automates and scales digital forensic processing workflows to handle large amounts of evidence in the cloud. 754
google/cloud-forensics-utils Tools for collecting and analyzing evidence from cloud platforms during incident response. 467
sekoialab/fastir_collector A tool for collecting and analyzing Windows system artefacts on live systems 507
coinbase/dexter A forensics acquisition framework for secure and extensible digital evidence collection and analysis. 126
darkquasar/azurehunter A tool to analyze and mine cloud forensic data from Azure and O365 audit logs. 771
hashlookup/hashlookup-forensic-analyser Analyze digital evidence by searching for files against a large public hash database and generating reports on findings. 126
swisscom/invoke-forensics Tools for automating forensic analysis with KAPE and RegRipper 109
rastrea2r/rastrea2r A tool for incident responders and security analysts to triage suspect systems, hunt for IOCs, and collect forensic evidence. 236
dissectmalware/officeforensictools A Python-based collection of tools for gathering forensic information from Office documents 26
johnlatwc/pypowershellxray Decodes and analyzes encoded PowerShell scripts to identify potential shellcode and reverse-engineered APIs. 215
google/giftstick Automated tool for collecting and uploading forensics evidence to the cloud. 140
codeyourweb/fastfinder Tools for detecting suspicious files and directories on Windows and Linux endpoints. 234