@jaredcatkinson jaredcatkinson released this Jan 30, 2016 · 74 commits to master since this release

Assets 4
  • Fixed major DataRun parsing bug
  • Added Nano Server compatibility!
  • Added new csproj for PowerShell v2 compatibility
    • New module PowerForensicv2 for PowerShell v2 compatibility

@jaredcatkinson jaredcatkinson released this Dec 16, 2015 · 76 commits to master since this release

Assets 3

Added 5 cmdlets:

  • Get-ForensicOfficeFileMru
  • Get-ForensicOfficeOutlookCatalog
  • Get-ForensicOfficePlaceMru
  • Get-ForensicOfficeTrustRecord
  • Get-ForesnicRunKey

A number of bugs fixed and code efficiencies added.

@jaredcatkinson jaredcatkinson released this Nov 22, 2015 · 110 commits to master since this release

Assets 3

This release features minor bug fixes, initial Pester tests, and updated help (thanks June!).

It also signifies the merging of the PowerForensics_Source and the PowerForensics repos.

@jaredcatkinson jaredcatkinson released this Nov 18, 2015 · 118 commits to master since this release

Assets 2

This is the official release of PowerForensics, a PowerShell module for performing hard drive forensic analysis.

The following features are included in this release:

  • DD utility
  • Boot Sector parsing
    • Master Boot Record
    • Guid Partition Table
  • NTFS File System Structure parsing
    • Volume Boot Record ($Boot)
    • $AttrDef
    • $Volume
    • Master File Table
    • UsnJrnl
    • File Slack Space
    • MFT Slack Space
    • Unallocated Space
  • Windows Event Log parsing
  • Windows Registry Hive parsing
    • Registry Keys
    • Registry Values
    • Amcache.hve
    • UserAssist
    • NetworkList
    • TypedUrls
    • System Security Identifier
    • System Timezone
  • Windows Artifact parsing
    • Prefetch
    • Scheduled Job
    • ShellLink
  • Custom binary parsing language called BinShred

There are also a few additional capabilities to copy files in a forensically sound manner. All features are implemented from the ground up and do not rely on the Windows API.