Collects live Windows artifacts, evaluates them against built-in detection rules, and tells you whether the host is compromised. One script, no dependencies.
-
Updated
Aug 24, 2026 - PowerShell
Collects live Windows artifacts, evaluates them against built-in detection rules, and tells you whether the host is compromised. One script, no dependencies.
ForensicTools automatise l’acquisition forensique multi-plateforme (Windows, Linux, macOS) : collecte d’artefacts volatils et persistants, capture mémoire, copie bit-à-bit des disques, chaîne de custody, gestion des dossiers d’enquête et orchestration d’outils d’analyse (Volatility3, Plaso, YARA, Sleuth Kit).
Digital forensics case study demonstrating evidence acquisition, integrity verification, deleted-data recovery, and artifact analysis.
Add a description, image, and links to the incident-response-forensics topic page so that developers can more easily learn about it.
To associate your repository with the incident-response-forensics topic, visit your repo's landing page and select "manage topics."