PowerShell Dfir

Open-source PowerShell projects categorized as Dfir

Top 12 PowerShell Dfir Projects

  1. sysmon-modular

    A repository of sysmon configuration modules

  2. InfluxDB

    InfluxDB – Built for High-Performance Time Series Workloads. InfluxDB 3 OSS is now GA. Transform, enrich, and act on time series data directly in the database. Automate critical tasks and eliminate the need to move data externally. Download now.

    InfluxDB logo
  3. sysmon-config

    Advanced Sysmon ATT&CK configuration focusing on Detecting the Most Techniques per Data source in MITRE ATT&CK, Provide Visibility into Forensic Artifact Events for UEBA, Detect Exploitation events with wide CVE Coverage, and Risk Scoring of CVE, UEBA, Forensic, and MITRE ATT&CK Events. (by ion-storm)

  4. AzureHunter

    A Cloud Forensics Powershell module to run threat hunting playbooks on data from Azure and O365

  5. MemProcFS-Analyzer

    MemProcFS-Analyzer - Automated Forensic Analysis of Windows Memory Dumps for DFIR

  6. ThreatHunting-Keywords

    Awesome list of keywords and artifacts for Threat Hunting sessions

  7. DetectionLabELK

    DetectionLabELK is a fork from DetectionLab with ELK stack instead of Splunk.

  8. Trawler

    PowerShell script helping Incident Responders discover potential adversary persistence mechanisms.

  9. SaaSHub

    SaaSHub - Software Alternatives and Reviews. SaaSHub helps you find the best software and product alternatives

    SaaSHub logo
  10. Collect-MemoryDump

    Collect-MemoryDump - Automated Creation of Windows Memory Snapshots for DFIR

  11. Win10

    Win 10/11 related research

  12. Queries

    SQLite queries (by kacos2000)

  13. WindowsDFIR

    Repository for different Windows DFIR related CMDs, PowerShell CMDlets, etc, plus workshops that I did for different conferences or events.

  14. Power-Response

    Powering Up Incident Response with Power-Response

NOTE: The open source projects on this list are ordered by number of github stars. The number of mentions indicates repo mentiontions in the last 12 Months or since we started tracking (Dec 2020).

PowerShell Dfir discussion

Log in or Post with

PowerShell Dfir related posts

  • Sysmon 15.0 is out now with advanced features

    2 projects | /r/sysadmin | 29 Jun 2023
  • Sharing a tool I developed to help Blue Teamers discover Persistence on Windows - please check it out!

    1 project | /r/u_1259iknow | 2 May 2023
  • Sharing a tool I developed to help Blue Teamers discover Persistence on Windows - please check it out!

    1 project | /r/netsec | 30 Apr 2023
  • User was hacked and sent out malware via their company email however unable to find out how?

    1 project | /r/cybersecurity | 25 Apr 2023
  • Sharing a new tool I made for aiding my analysis of persistence mechanisms on Windows - Trawler

    1 project | /r/computerforensics | 24 Apr 2023
  • Splunk & Sysmon as SIEM

    1 project | /r/Splunk | 11 Apr 2023
  • Looking for inputs and validation for this network setup.

    2 projects | /r/AskNetsec | 24 Feb 2023
  • A note from our sponsor - InfluxDB
    www.influxdata.com | 20 May 2025
    InfluxDB 3 OSS is now GA. Transform, enrich, and act on time series data directly in the database. Automate critical tasks and eliminate the need to move data externally. Download now. Learn more →

Index

What are some of the best open-source Dfir projects in PowerShell? This list will help you:

# Project Stars
1 sysmon-modular 2,775
2 sysmon-config 801
3 AzureHunter 783
4 MemProcFS-Analyzer 623
5 ThreatHunting-Keywords 570
6 DetectionLabELK 548
7 Trawler 316
8 Collect-MemoryDump 240
9 Win10 183
10 Queries 79
11 WindowsDFIR 77
12 Power-Response 63

Sponsored
InfluxDB – Built for High-Performance Time Series Workloads
InfluxDB 3 OSS is now GA. Transform, enrich, and act on time series data directly in the database. Automate critical tasks and eliminate the need to move data externally. Download now.
www.influxdata.com

Did you know that PowerShell is
the 40th most popular programming language
based on number of references?