AndrewRathbun / VanillaWindowsRegistryHivesView external linksLinks
A repo that contains a recursive dump from the ROOT key of every Windows Registry hive (using KAPE) from a vanilla (clean) install of every Windows OS version to compare and see what's been added with each update.
☆54Oct 29, 2025Updated 3 months ago
Alternatives and similar repositories for VanillaWindowsRegistryHives
Users that are interested in VanillaWindowsRegistryHives are comparing it to the libraries listed below
Sorting:
- A repo that contains recursive directory listings (using PowerShell) of a vanilla (clean) install of every Windows OS version to compare …☆191Oct 29, 2025Updated 3 months ago
- Various PowerShells scripts I've made (or others have made) to automate some of the boring stuff in my everyday DFIR journey!☆51Jan 9, 2026Updated last month
- A script that updates KAPE (using Get-KAPEUpdate.ps1) as well as EZ Tools (within .\KAPE\Modules\bin) and the ancillary files that enhanc…☆59Jun 24, 2025Updated 7 months ago
- Parser for Sdba memory pool tags☆21Jul 16, 2021Updated 4 years ago
- A repo to centralize some of the regular expressions I've found useful over the course of my DFIR career.☆107Nov 23, 2022Updated 3 years ago
- Extension blocks as found in ShellBags and other places in the Registry☆25Jan 7, 2025Updated last year
- Plugins for parsing CSV files in Timeline Explorer. This project allows for anyone to add more supported files (i,e. they get a Line #/ta…☆28May 5, 2025Updated 9 months ago
- Get USB Devices from Registry hives☆22Nov 15, 2021Updated 4 years ago
- A Windows registry file parser written in Rust☆41Oct 30, 2025Updated 3 months ago
- Evtx Log (xml) Browser☆56Mar 12, 2023Updated 2 years ago
- Registry Explorer bookmark definitions☆44Dec 19, 2024Updated last year
- A repo for centralizing ongoing research on the new Windows 10/11 DFIR artifact, EventTranscript.db.☆43Jul 18, 2022Updated 3 years ago
- PowerShell scripts to aid investigators when utilizing O365 and Magnet Axiom.☆12Aug 26, 2024Updated last year
- Repo with supporting material for the talk titled "Cracking the Beacon: Automating the extraction of implant configurations"☆11Feb 6, 2025Updated last year
- Library to process OLE compound file format. This is a work in progress and was initially written for jumplist parsing (for which it does…☆19Feb 2, 2025Updated last year
- Automating forensic data extraction, reduction, and overall triage of cold disk and memory images.☆21Mar 12, 2019Updated 6 years ago
- Limit P-States on NVIDIA GPUs when a user-defined list of processes are not in the foreground to reduce power consumption☆26Jun 24, 2025Updated 7 months ago
- Automatic/Custom Destinations & LNK (MS-SHLLINK) Browser☆42Updated this week
- A curated list of KAPE-related resources☆179May 1, 2025Updated 9 months ago
- Documentation repository☆47Aug 30, 2024Updated last year
- RegFineViewer is an utility to visualize and navigate easily the Windows Registry☆18Jan 20, 2021Updated 5 years ago
- This script will generate hashes (MD5, SHA1, SHA256), submit the MD5 to Virus Total, and produce a text file with the results.☆15Jul 13, 2023Updated 2 years ago
- No catchy tagline.☆13Sep 29, 2023Updated 2 years ago
- $MFT parser (from live systems or a copy of the $MFT) and raw file copy utility☆38Jul 18, 2024Updated last year
- Windows Registry Knowledge Base☆195Dec 23, 2025Updated last month
- ☆76Feb 7, 2026Updated last week
- A modified fork of Be.HexEditor for use in debug tools☆14Jan 5, 2022Updated 4 years ago
- ☆60Jan 28, 2026Updated 2 weeks ago
- This is a repository for reporting any issues in any of my software☆13May 15, 2018Updated 7 years ago
- Sharing my BITS☆13Feb 23, 2018Updated 7 years ago
- NTFS file system specimens☆13Jul 3, 2023Updated 2 years ago
- Indicators of Normality☆11Jul 22, 2022Updated 3 years ago
- Fork this repo! Do a Pull Request! As many times as you want! Learn the ins and outs of how to contribute to GitHub! Make your mistakes h…☆14Jun 21, 2024Updated last year
- A repository hosting example goodware evtx logs containing sample software installation and basic user interaction☆86Dec 17, 2025Updated last month
- Splunk Technology-AddOn for Aurora Sigma-Based EDR Agent. It helps parse and configure the necessary inputs to neatly consume Aurora EDR …☆13Sep 27, 2022Updated 3 years ago
- Windows Disk Cleanup with Hidden Options☆18Sep 28, 2024Updated last year
- ☆12Jun 3, 2022Updated 3 years ago
- Powershell script to monitor a wireless adapter every second until it disconnects.☆14May 15, 2024Updated last year
- A sample VHDX file with multiple verbose examples of forensic and anti-forensics artifacts. Meant to be basic and can be expanded upon. P…☆27Jan 2, 2023Updated 3 years ago