/PSGumshoe

Primary LanguagePowerShellMIT LicenseMIT

PSGumshoe

PSGumshoe is a Windows PowerShell module for the collection of OS and domain artifacts for the purposes of performing live response, hunt, and forensics.

The module focuses on being as forensically sound as possible using existing Windows APIs to achieve the collection of information from the target host.

For information on how to contribute and use the module please refer to the documentation in the Wiki