PS-Remote Get MFT

This playbook leverages the Windows built-in PowerShell and WinRM capabilities to connect to a Windows host to acquire and export the MFT (Master File Table) as forensic evidence for further analysis.

Pack
WindowsForensics
Tasks
12

Inputs

Outputs

Commands used