PS-Remote Acquire Host Forensics

This playbook allows the user to gather multiple forensic data from a Windows endpoint including network traffic, MFT (Master File Table), and registry export by using the PS Remote automation which enables connecting to a Windows host without the need to install any 3rd-party tools using just native Windows management tools.

Pack
WindowsForensics
Tasks
11

Inputs

Outputs