PowerShell Dfir

Open-source PowerShell projects categorized as Dfir

Top 7 PowerShell Dfir Projects

  • sysmon-modular

    A repository of sysmon configuration modules

    Project mention: Is Windows Defender for Business any good? | reddit.com/r/cybersecurity | 2022-11-09

    Agree. Harden your endpoints (if unsure where to start consider hardening kitty, https://github.com/scipag/HardeningKitty) and harden Defender (https://0ut3r.space/2022/03/06/windows-defender/). Add Sysmon with a good config (https://github.com/olafhartong/sysmon-modular) and you've reached a good starting point.

  • AzureHunter

    A Cloud Forensics Powershell module to run threat hunting playbooks on data from Azure and O365

  • Zigi

    Close all those tabs. Zigi will handle your updates.. Zigi monitors Jira and GitHub updates, pings you when PRs need approval and lets you take fast actions - all directly from Slack! Plus it reduces cycle time by up to 75%.

  • DetectionLabELK

    DetectionLabELK is a fork from DetectionLab with ELK stack instead of Splunk.

    Project mention: Work setup | reddit.com/r/pop_os | 2022-08-27

    Detection Lab ELK: https://github.com/cyberdefenders/DetectionLabELK

  • WELA

    WELA (Windows Event Log Analyzer): The Swiss Army knife for Windows Event Logs! ゑ羅(ウェラ)

    Project mention: Yamato-Security/WELA: WELA (Windows Event Log Analyzer): The Swiss Army knife for Windows Event Logs! ゑ羅(ウェラ) | reddit.com/r/cyber_deception | 2021-12-26
  • Power-Response

    Powering Up Incident Response with Power-Response

  • Queries

    SQLite queries (by kacos2000)

    Project mention: SQLite query repository? | reddit.com/r/computerforensics | 2022-01-20

    https://github.com/kacos2000/Queries - Costas is very underappreciated. He's amazing

  • WindowsDFIR

    Repository for different Windows DFIR related CMDs, PowerShell CMDlets, etc, plus workshops that I did for different conferences or events.

  • Scout APM

    Truly a developer’s best friend. Scout APM is great for developers who want to find and fix performance issues in their applications. With Scout, we'll take care of the bugs so you can focus on building great things 🚀.

NOTE: The open source projects on this list are ordered by number of github stars. The number of mentions indicates repo mentiontions in the last 12 Months or since we started tracking (Dec 2020). The latest post mention was on 2022-11-09.

PowerShell Dfir related posts


What are some of the best open-source Dfir projects in PowerShell? This list will help you:

Project Stars
1 sysmon-modular 2,034
2 AzureHunter 636
3 DetectionLabELK 472
4 WELA 468
5 Power-Response 58
6 Queries 57
7 WindowsDFIR 53
Build time-series-based applications quickly and at scale.
InfluxDB is the Time Series Data Platform where developers build real-time applications for analytics, IoT and cloud-native services in less time with less code.