PoShFoTo is the PowerShell Forensics Toolkit, which contains a dozen PowerShell tools that allow you to do basic incident response and malware forensics. It includes Hex Dumper, Registry timeline generator, File timeline generator, and PE-block analyzer.
You can download it from the following link: https://packetstormsecurity.com/files/download/137218/PoShFoTo.zip
Source: https://packetstormsecurity.com/files/137218/PoShFoTo-PowerShell-Forensics-Toolkit.html

