PSRecon
PSRecon gathers data from a remote Windows host using PowerShell (v2 or later), organizes the data into folders, hashes all extracted data, hashes PowerShell and various system properties, and sends the data off to the security team. The data can be pushed to a share, sent over…
- from
- Incident Response, Cybersecurity Blue Team
- added
- 2026-10-10
- likes
- 0
Incident Response › IR Tools Collection > Windows Evidence Collection: “PSRecon gathers data from a remote Windows host using PowerShell (v2 or later), organizes the data into folders, hashes all extracted data, hashes PowerShell and various system properties, and sends the data off to the security team. The data can be pushed to a share, sent over…”
Cybersecurity Blue Team › Security monitoring > Threat hunting: “PSHunt-like tool for analyzing remote Windows systems that also produces a self-contained HTML report of its findings.”