Skip to content
Peter Reuterås edited this page Nov 18, 2023 · 36 revisions

Welcome to the dfirws wiki!

The goal for dfirws is to have useful tools for DFIR and IR work in an easy to access way in a Windows Sandbox.

Start by reading Getting started and continue with Customise dfirws.

Trying to add Jupyter Notebooks under setup/jupyter to be able to automate investigations as much as possible. At the moment there are notebooks for

Below are sections similar to the REMnux docs documentation with examples on how to use the tools included in dfirws.

Read more about available tools here. If you miss a tool, find a problem och like to change a default configuration please submit an issue on GitHub for better control and traceability.