Jack Halstead's repositories

IRCP

A series of PowerShell scripts to automate collection of forensic artefacts in most Incident Response environments

Language:PowerShellLicense:MITStargazers:64Issues:3Issues:2

IR-Incident-Event-Timeline

Excel-based Event Timeline with customizable legend for Artefacts, Assets and Activity Type

NTUSER-UsrClass-Extractor

PowerShell script to pull NTUser & UsrClass from live hosts, mounted images or KAPE targets folder

Language:PowerShellStargazers:1Issues:0Issues:0