PowerTriage Windows

Native tooling for Windows live triage: portable, free of external dependencies, and built for real DFIR investigations.

PowerTriage Windows Screenshot
PowerTriage execution interface on Windows

What is PowerTriage Windows?

PowerTriage Windows is a native PowerShell tool for Windows 10, 11, and Server focused on collecting high-value forensic artifacts with simple deployment, low operational friction, and structured output ready for technical review.

It is designed for direct execution on compromised systems, remote live response, and EDR/XDR environments. Some additional capabilities remain in development or evaluation before publication.

Designed for Real DFIR

It is meant to stay genuinely useful to the DFIR community: strong at live triage, portable, and still capable of producing useful context when elevation is unavailable.

Common Use Cases

PowerTriage Windows is oriented towards DFIR teams, SOC, and incident response.

  • ✔Live Response on compromised systems
  • ✔Execution from EDR/XDR or remote consoles
  • ✔Initial triage before deeper forensic analysis
  • ✔Support for internal and corporate investigations
  • ✔Useful collection in degraded mode without admin rights

Collected Forensic Artifacts

Execution & Activity

Prefetch, Amcache, ShimCache, BAM/DAM, and process execution evidence.

User Activity

Jump Lists, Recent Files (LNK), ShellBags, Recycle Bin, and Profiles.

Network & Connections

Active Connections (TCP/UDP), DNS Cache, ARP Table, Routes, and Firewall Rules.

Web Browsers

History, Cookies, and Logins from Chrome, Edge, Firefox, Opera, and Brave.

Email & Cloud

Outlook (OST/PST), Logs and Metadata from OneDrive, Teams, Google Drive, and Dropbox.

System & Security

Event Logs (Security, Sysmon, RDP), Services, Scheduled Tasks, Autoruns, and USB History.

Execution Modes and Current Scope

Quick

Rapid collection of key artifacts for immediate context.

Full

Broader collection for deeper investigation on the live host.

Custom

Selective execution of modules according to the investigation.

No Admin

It can continue in a degraded mode when elevated privileges are not available.

PowerTriage Windows Capabilities

PowerTriage Windows evolves continuously. Some capabilities are publicly available, while others remain in development, validation, or internal use before publication.

Capability Status
Windows live triageAvailable
Modular artifact collectionAvailable
User, system, process, network, event, and browser artifactsAvailable
Basic hashing and packaged outputAvailable
Offline mounted-volume collectionIn development
Offline hives and selected NTFS artifactsUnder evaluation
Expanded integrity and technical traceability recordsUnder evaluation
Structured reportingUnder evaluation
Structured result packaging for complex casesUnder evaluation

Output and Formats

Structured results ready for subsequent analysis.

  • ✔Artifact-oriented structured output
  • ✔SHA256 hashing of collected artifacts
  • ✔Packaged output for transfer and archive
  • ✔Structure prepared for downstream correlation and analysis

Fit within PowerForensics

PowerTriage Windows CE is the live acquisition and triage layer within the PowerForensics ecosystem. Its output is prepared for later review in Chronos and Nexus.

Technical Documentation

Review requirements, execution parameters, and the current public scope.