InfluxDB 3 OSS is now GA. Transform, enrich, and act on time series data directly in the database. Automate critical tasks and eliminate the need to move data externally. Download now. Learn more →
Top 12 PowerShell Dfir Projects
-
-
InfluxDB
InfluxDB – Built for High-Performance Time Series Workloads. InfluxDB 3 OSS is now GA. Transform, enrich, and act on time series data directly in the database. Automate critical tasks and eliminate the need to move data externally. Download now.
-
sysmon-config
Advanced Sysmon ATT&CK configuration focusing on Detecting the Most Techniques per Data source in MITRE ATT&CK, Provide Visibility into Forensic Artifact Events for UEBA, Detect Exploitation events with wide CVE Coverage, and Risk Scoring of CVE, UEBA, Forensic, and MITRE ATT&CK Events. (by ion-storm)
-
AzureHunter
A Cloud Forensics Powershell module to run threat hunting playbooks on data from Azure and O365
-
MemProcFS-Analyzer
MemProcFS-Analyzer - Automated Forensic Analysis of Windows Memory Dumps for DFIR
-
-
-
Trawler
PowerShell script helping Incident Responders discover potential adversary persistence mechanisms.
-
SaaSHub
SaaSHub - Software Alternatives and Reviews. SaaSHub helps you find the best software and product alternatives
-
-
-
-
WindowsDFIR
Repository for different Windows DFIR related CMDs, PowerShell CMDlets, etc, plus workshops that I did for different conferences or events.
-
PowerShell Dfir discussion
PowerShell Dfir related posts
-
Sysmon 15.0 is out now with advanced features
-
Sharing a tool I developed to help Blue Teamers discover Persistence on Windows - please check it out!
-
Sharing a tool I developed to help Blue Teamers discover Persistence on Windows - please check it out!
-
User was hacked and sent out malware via their company email however unable to find out how?
-
Sharing a new tool I made for aiding my analysis of persistence mechanisms on Windows - Trawler
-
Splunk & Sysmon as SIEM
-
Looking for inputs and validation for this network setup.
-
A note from our sponsor - InfluxDB
www.influxdata.com | 20 May 2025
Index
What are some of the best open-source Dfir projects in PowerShell? This list will help you:
# | Project | Stars |
---|---|---|
1 | sysmon-modular | 2,775 |
2 | sysmon-config | 801 |
3 | AzureHunter | 783 |
4 | MemProcFS-Analyzer | 623 |
5 | ThreatHunting-Keywords | 570 |
6 | DetectionLabELK | 548 |
7 | Trawler | 316 |
8 | Collect-MemoryDump | 240 |
9 | Win10 | 183 |
10 | Queries | 79 |
11 | WindowsDFIR | 77 |
12 | Power-Response | 63 |