Parser for Sdba memory pool tags
☆21Jul 16, 2021Updated 4 years ago
Alternatives and similar repositories for SdbaParser
Users that are interested in SdbaParser are comparing it to the libraries listed below
Sorting:
- Forensic cheatsheets for use with cheat☆15Dec 2, 2021Updated 4 years ago
- Just Another broken Registry Parser (JARP)☆16May 23, 2024Updated last year
- ☆11Aug 3, 2018Updated 7 years ago
- A repo for centralizing ongoing research on the new Windows 10/11 DFIR artifact, EventTranscript.db.☆44Jul 18, 2022Updated 3 years ago
- Backstage Parser☆33Jun 23, 2022Updated 3 years ago
- Python web app for previewing data in a Chrome Profile Folder☆24Jul 1, 2024Updated last year
- Evtx Log (xml) Browser☆56Mar 12, 2023Updated 3 years ago
- http://moaistory.blogspot.com/2018/10/winsearchdbanalyzer.html☆127Jul 20, 2024Updated last year
- Browse Windows Prefetch versions: 17,23,26,30v1/2,31 & some of SuperFetch .7db/.db's☆64Dec 18, 2024Updated last year
- Set of utilities for getting information about Windows Events☆15Jun 5, 2018Updated 7 years ago
- Decode security descriptors in $Secure on NTFS☆22Feb 24, 2022Updated 4 years ago
- macos-collector - Automated Collection of macOS Forensic Artifacts for DFIR☆37Updated this week
- CryptnetURLCacheParser is a tool to parse CryptAPI cache files☆21Aug 3, 2024Updated last year
- A C# (.NET 6) tool to compare the file signature of files recursively and inform the user of matches and mismatches☆16Nov 29, 2024Updated last year
- Google Filestream Forensic Tool☆22Mar 10, 2022Updated 4 years ago
- An exercise to practice deobfuscating PowerShell Scripts.☆26Feb 10, 2023Updated 3 years ago
- ☆24Mar 12, 2025Updated last year
- Quick ESXi Log Parser☆30Oct 20, 2025Updated 5 months ago
- Convert a variety of log formats to CSV while enriching detected IPs with Geolocation, ASN, DNS, WhoIs, Shodan InternetDB and Threat Indi…☆110Feb 6, 2026Updated last month
- An efficient tool for search files, directories, and alternate data streams directly from NTFS image files.☆28Mar 12, 2026Updated last week
- This is to edit a training forensic image file (raw/dd) and zero out all the unnecessary files.☆11Jun 21, 2025Updated 8 months ago
- Carve file metadata from NTFS index ($I30) attributes☆71Feb 3, 2024Updated 2 years ago
- StickyParser - Sticky Notes Forensic. A Windows Sticky Notes Praser (snt and plum.sqlite supported). Additional Feature: SQLite Recovery …☆21Jul 18, 2023Updated 2 years ago
- The home of the BriMor Labs rdpieces Perl script that tries to rebuild parsed RDP Bitmap Cache images☆89Aug 29, 2023Updated 2 years ago
- Carve $MFT records from a chunk of data (for instance a memory dump)☆16Aug 21, 2016Updated 9 years ago
- Vault of Windows Registry forensic artifacts☆28Nov 12, 2025Updated 4 months ago
- /ˈhäjˌpäj/ "a confused mixture."☆13Mar 5, 2026Updated 2 weeks ago
- OneDrive log .ODL reader☆161Nov 3, 2024Updated last year
- MS Word (DOCx) Parsing Tool☆25Updated this week
- Yet another registry parser☆137Apr 15, 2022Updated 3 years ago
- Project based on RegRipper, to extract add'l value/pivot points from TLN events file☆89Feb 9, 2025Updated last year
- Windows Forensics Salt States☆21Mar 11, 2026Updated last week
- Search datasets for Bitlocker recovery files and triage live systems for Bitlocker keys.☆52Jan 26, 2025Updated last year
- ☆20Jan 10, 2025Updated last year
- Win 10/11 related research☆198Dec 19, 2023Updated 2 years ago
- Tools and scripts to deploy and manage OpenRelik instances☆16Mar 3, 2026Updated 2 weeks ago
- Windows link file (shortcuts) examiner☆68Jun 9, 2024Updated last year
- PowerShell scripts to aid investigators when utilizing O365 and Magnet Axiom.☆12Aug 26, 2024Updated last year
- The ultimate streamline for Volatility 3. Speed up process of memory artifacts extraction phase☆14Dec 19, 2024Updated last year