PowerShell script utilized to pull several forensic artifacts from a live Win7 and WinXP system without WINRM.
irCRpull is a PowerShell script utilized to pull several system artifacts, utilizing the free tool CrowdResponse, from a live Win7+ system on your network.
PowerShell Memory Pulling script
Powershell script to launch a remote netsh packet trace and pull it for analysis.
Script to process the output from IRFartpull
Powershell script to process McAfee Quarantine .bup files.