Rapid Triage Examination & Analysis Tools
Download and Setup
PS C:\Users\johndoe\Desktop\Get-ZimmermanTools> .\Get-ZimmermanTools.ps1MAC(b) Times in NTFS
Example Commands
PS C:\Users\johndoe\Desktop\Get-ZimmermanTools\net6> .\MFTECmd.exe -f 'C:\Users\johndoe\Desktop\forensic_data\kape_output\D\$MFT' --de 0x16169Investigation Tools Overview
MFT File Structure
Windows Event Logs
Windows Registry Analysis
Program Execution Artifacts
Advanced Analysis
Key Commands for Forensic Analysis
PowerShell Commands
Other Important Scripts and Commands
Last updated