Skip to content

Windows digital forensics and incident response scripts

Notifications You must be signed in to change notification settings

pranatdayal/forensics

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

19 Commits
 
 
 
 
 
 
 
 

Repository files navigation

DFIR

Pranat Dayal Digital forensics and incident response scripts

SysArtifacts.ps1:

Collects various system artifacts from a windows computer for the purpose of Digital Forensics and Incident response

ParseMFT.ps1:

Parses through a CSV dump of $MFT and prints out:

  - Filename 
  
  - Filepath 
  
  - Timestamps

It also dumps $DATA from a particular file and can identify timestomping instances

About

Windows digital forensics and incident response scripts

Topics

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published