This project is a Python-based digital forensics and incident response (DFIR) triage tool for Windows systems. It automates the collection of volatile and non-volatile forensic artifacts including running processes, network connections, scheduled tasks, registry hives, event logs, prefetch files, and browser history into a structured output directory. It is aimed at incident responders performing rapid initial triage and evidence preservation on Windows endpoints.
