Public technical tools and visual modules for DFIR investigations with operational clarity.
PowerForensics groups tools aligned with different DFIR phases: collection, normalization, timeline analysis, and relational analysis.
Native PowerShell tooling for live triage and rapid artifact acquisition on Windows. Portable, dependency-free, and practical for direct execution, live response, or EDR/XDR workflows.
Standalone Bash tooling for fast triage on Linux systems. Extracts logs, sessions, connections, scheduled tasks, users, cronjobs, and persistence artifacts for later technical review.
Specialized tooling for IoT and embedded environments. Reviews configurations, authentication data, credentials, critical services, and other relevant elements in non-traditional infrastructures.
Conversion and normalization engine that turns evidence and logs into structures consumable by the ecosystem, ready for timeline work, correlation, and technical enrichment.
Visual module focused on timeline reconstruction. Helps analysts order events, sequences, and relevant activity to add chronological context to an investigation.
Graph-based relational module used to represent connections between entities, artifacts, systems, users, and events within an investigation.
PowerForensics is designed to support different DFIR phases, from initial evidence acquisition to normalization, timeline reconstruction, and relational analysis.
Acquire relevant artifacts with PowerTriage on Windows, Linux, or IoT depending on the affected environment.
Transform data and logs into consumable structures with PowerLens to simplify reading, filtering, and reuse.
Reconstruct event sequences with Chronos to identify key moments, pivots, and transitions.
Explore connections between entities with Nexus to correlate users, systems, artifacts, and activity.
PowerTriage is a native PowerShell tool designed for Windows (10/11/Server) that collects and reviews key system artifacts without external dependencies and with low operational friction.
Incident response teams, corporate DFIR, SOC, hybrid environments, or air-gapped scenarios.
PowerTriage Windows evolves continuously. Some capabilities are available publicly, while others remain in development, validation, or internal use before publication.
Standalone Bash tooling for rapid triage on Linux systems. Extracts logs, sessions, active connections, scheduled tasks, users, cronjobs, and persistence artifacts.

Specialized version for embedded environments. Reviews configurations, credentials, critical services, and vulnerabilities with lightweight, reusable output.

I am open to technical feedback, collaborations, and improvements around the PowerForensics ecosystem.