Andrea Fortuna wrote a blog about PowerForensics: the PowerShell infrastructure for forensic analysis of the hard drive. In it, he talks about the PostForensiсs.
The purpose of PowerForensics is to provide an all-encompassing framework for forensic analysis of the hard drive. Currently, PowerForensics supports NTFS and FAT file systems, and work began on the extended file system and support for HFS +.
Andrea also describes a new technology file system (NTFS), and Features and CmdLets. Andrea also describes a new file system for technology (NTFS), as well as Opportunities and CmdLets. In conclusion, he gives recommendations.