IncidentCapsule

1.2.0

Read-only Windows first-response evidence collection with offline reporting and hardened SHA-256 integrity verification.

Minimum PowerShell version

5.1

Installation Options

Copy and Paste the following command to install this package using PowerShellGet More Info

Install-Module -Name IncidentCapsule -RequiredVersion 1.2.0

Copy and Paste the following command to install this package using Microsoft.PowerShell.PSResourceGet More Info

Install-PSResource -Name IncidentCapsule -Version 1.2.0

You can deploy this package directly to Azure Automation. Note that deploying packages with dependencies will deploy all the dependencies to Azure Automation. Learn More

Manually download the .nupkg file to your system's default download location. Note that the file won't be unpacked, and won't include any dependencies. Learn More

Owners

Copyright

(c) 2026 xGreeny and Incident Capsule contributors. MIT License.

Package Details

Author(s)

  • xGreeny

Tags

IncidentResponse DFIR Windows PowerShell Triage SecurityOperations Evidence Forensics BlueTeam

Functions

Export-IncidentCapsuleData Get-IncidentCapsuleProfile Invoke-IncidentCapsule Test-IncidentCapsuleReadiness Test-IncidentCapsuleIntegrity

PSEditions

Desktop Core

Dependencies

This module has no dependencies.

Release Notes

Evidence depth and authentic handoff: InstalledSoftware, Certificates, ExecutionArtifacts, and Devices collectors, detached CMS manifest signing with -SigningCertificate and -RequireSignature, JSONL evidence export, extended lateral-movement event channels, and PowerShell Gallery distribution.

FileList

Version History

Version Downloads Last updated
1.3.1 9 7/22/2026
1.3.0 5 7/22/2026
1.2.1 5 7/22/2026
1.2.0 (current version) 4 7/22/2026