Modular, agent-less forensic triage framework for rapid Windows & Linux artifact collection and memory acquisition
-
Updated
Jan 8, 2026 - PowerShell
Modular, agent-less forensic triage framework for rapid Windows & Linux artifact collection and memory acquisition
A PowerShell script for live forensic data collection on Windows. No external dependencies required.
Powerful investigation toolkit for deeper forensic analysis
RegEx is a portable Windows Registry Acquisition tool designed for forensic investigators. It runs directly from a USB device, requires no installation, and extracts targeted registry hives using predefined acquisition profiles. Built for speed, reliability, and zero-footprint operation.
Add a description, image, and links to the windows-forensics topic page so that developers can more easily learn about it.
To associate your repository with the windows-forensics topic, visit your repo's landing page and select "manage topics."