PSRecon gathers data from a remote Windows host using PowerShell (v2 or later), organizes the data into folders, hashes all extracted data, hashes PowerShell and various system properties, and sends the data off to the security team. The data can be pushed to a share, sent over email, or retained locally.
☆493Jul 29, 2017Updated 8 years ago
Alternatives and similar repositories for PSRecon
Users that are interested in PSRecon are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- PowerForensics provides an all in one platform for live disk forensic analysis☆1,433Nov 16, 2023Updated 2 years ago
- CimSweep is a suite of CIM/WMI-based tools that enable the ability to perform incident response and hunting operations remotely across al…☆659Aug 19, 2019Updated 6 years ago
- A Powershell incident response framework☆1,653Nov 22, 2022Updated 3 years ago
- Exploit the credentials present in files and memory☆844May 25, 2023Updated 2 years ago
- Powershell Threat Hunting Module☆291Sep 21, 2016Updated 9 years ago
- Open source password manager - Proton Pass • AdSecurely store, share, and autofill your credentials with Proton Pass, the end-to-end encrypted password manager trusted by millions.
- This repo is for WMIOps, a powershell script which uses WMI for various purposes across a network.☆387Jun 25, 2024Updated last year
- A PowerShell Module Dedicated to Reverse Engineering☆898Aug 20, 2021Updated 4 years ago
- Currently not updated for WMIEvent module...☆263Feb 23, 2016Updated 10 years ago
- Query and report user logons relations from MS Windows Security Events☆243Aug 9, 2018Updated 7 years ago
- PowerShell Runspace Post Exploitation Toolkit☆1,550Aug 2, 2019Updated 6 years ago
- ☆520Jan 26, 2021Updated 5 years ago
- This is a PowerShell based tool that is designed to act like a RAT. Its interface is that of a shell where any command that is supported …☆850Jun 25, 2024Updated last year
- A PowerShell TCP/IP swiss army knife.☆576May 1, 2017Updated 9 years ago
- GoFetch is a tool to automatically exercise an attack plan generated by the BloodHound application.☆636Jun 20, 2017Updated 8 years ago
- Proton VPN Special Offer - Get 70% off • AdSpecial partner offer. Trusted by over 100 million users worldwide. Tested, Approved and Recommended by Experts.
- A PowerShell based utility for the creation of malicious Office macro documents.☆1,108Nov 3, 2017Updated 8 years ago
- A post-exploitation powershell tool for extracting juicy info from memory.☆1,864Jun 28, 2024Updated last year
- Collection of PowerShell scripts☆452Dec 18, 2017Updated 8 years ago
- Powershell module to assist in attacking Exchange/Outlook Web Access