PowerTriage
1.0.1
It collects critical artifacts (Network, Process, Persistence, System, Browsers) and packages them for analysis.
Features:
- Zero Dependencies: Runs on standard PowerShell 5.1+
- Modular: Full or Minimal collection modes.
- Browser For
It collects critical artifacts (Network, Process, Persistence, System, Browsers) and packages them for analysis.
Features:
- Zero Dependencies: Runs on standard PowerShell 5.1+
- Modular: Full or Minimal collection modes.
- Browser Forensics: Chrome, Edge, Firefox, Opera, Brave (History, Cookies, Extensions, Sync Status).
- System Triage: Network connections, Processes, Services, Scheduled Tasks, Registry Autoruns.
- Output: Structured CSV/TXT reports and a zipped final package.
Installation Options
Owners
Copyright
(c) 2025 Jesus Angosto. All rights reserved.
Package Details
Author(s)
- Jesus Angosto
Tags
DFIR Forensics IncidentResponse Triage PowerShell
Functions
Show-Banner WriteLog WriteHash Get-NetworkInfo Get-SmbInfo Get-Autoruns Get-ScheduledTasksInfo Get-FirewallRules Get-ProcessAndHashes Print-ProcessTree Get-Tree Get-USBHistory Get-Evtx PowerShell_Commands Get-LocalGroups Get-EnvVars Get-Services Get-ClipboardContent RecentFiles ActivitiesCache CopyPrefetch RecycleBin Get-DNS Installed_Software Collect-BrowserArtifacts Get-RdpConnections Get-SystemConfig Export-ForensicArtifactsFromVSS Get-CloudStorageArtifacts Get-RemoteAccessArtifacts Get-EmailArtifacts Export-ForensicCatalog Zip-Results
Dependencies
This script has no dependencies.
FileList
- PowerTriage.nuspec
- PowerTriage.ps1
Version History
| Version | Downloads | Last updated |
|---|---|---|
| 1.0.1 (current version) | 5 | 3/1/2026 |
| 1.0.0 | 4 | 3/1/2026 |