PowerShell Digital Forensics & Incident Response Scripts.
-
Updated
Sep 24, 2025 - PowerShell
PowerShell Digital Forensics & Incident Response Scripts.
PowerShell script designed to help Incident Responders collect forensic evidence from local and remote Windows devices.
Over 100K open-source YARA signatures evaluated against over 280K files to give insights into the performance of each YARA rule.
PowerShell and VBScript tools for automating Active Directory workflows,securing system operations, and supporting forensic procedures. Designed for Windows Servers and workstations, these solutions improve accuracy, scalability, and compliance—enhancing performance, reliability, and cybersecurity posture across enterprise IT environments worldwide
A tool for fetching DFIR and other GitHub tools.
PowerShell tool that helps to parse and analyze Ivanti Secure Connect logs, this tool could help in forensic investigations to have more visibility and more detailed view of the "vc0" logs.
Evidence Collection & Handling Orchestrator
Install every tool and every needed software for your DFIR (/SRE/PEN/OSINT/TCI) workstation. This Tool is doing the work for you, everything after installing Windows (and update).
Windows artifact collector to facilitate forensic work
DFIR-Orc GetThis tool configuration generator.
Add a description, image, and links to the forensics-tools topic page so that developers can more easily learn about it.
To associate your repository with the forensics-tools topic, visit your repo's landing page and select "manage topics."