EricZimmerman / AppCompatCacheParser
AppCompatCache (shimcache) parser. Supports Windows 7 (x86 and x64), Windows 8.x, and Windows 10
☆111Updated this week
Alternatives and similar repositories for AppCompatCacheParser:
Users that are interested in AppCompatCacheParser are comparing it to the libraries listed below
- Parses amcache.hve files, but with a twist!☆124Updated this week
- Command line access to the Registry☆134Updated this week
- Parses RecentFileCacheParser.bcf files☆25Updated last week
- ☆61Updated last week
- Parser for $UsnJrnl on NTFS☆108Updated 2 years ago
- Script for parsing Symantec Endpoint Protection logs, VBNs, and ccSubSDK database.☆63Updated 2 years ago
- Windows Prefetch parser. Supports all known versions from Windows XP to Windows 10.☆108Updated last week
- MFT parser☆65Updated last week
- C# based evtx parser with lots of extras☆285Updated this week
- A better strings utility!☆123Updated this week
- Windows Registry Knowledge Base☆169Updated 3 months ago
- Lnk Explorer Command line edition!!☆286Updated last week
- ☆19Updated last week
- A repository that maps API calls to Sysmon Event ID's.☆117Updated 2 years ago
- Cobalt Strike Beacon configuration extractor and parser.☆149Updated 3 years ago
- Parser for $LogFile on NTFS☆192Updated last year
- Memory Baseliner is a script that can compare two windows memory images or perform frequency of occurrence / data stacking analysis on mu…☆50Updated last year
- $MFT directory tree reconstruction & FILE record info☆296Updated 3 months ago
- YARA rule analyzer to improve rule quality and performance☆95Updated 3 weeks ago
- Parses $MFT from NTFS file systems☆210Updated this week
- ☆296Updated 4 years ago
- ☆37Updated 3 years ago
- Prefetch Explorer Command Line☆235Updated this week
- Carve file metadata from NTFS index ($I30) attributes☆62Updated 11 months ago
- Extract BITS jobs from QMGR queue and store them as CSV records☆74Updated 6 months ago
- ☆39Updated this week
- ☆47Updated this week
- "Evolving AppCompat/AmCache data analysis beyond grep"☆199Updated 3 years ago
- RdpCacheStitcher is a tool that supports forensic analysts in reconstructing useful images out of RDP cache bitmaps.☆245Updated last year
- EVTXtract recovers and reconstructs fragments of EVTX log files from raw binary data, including unallocated space and memory images.☆193Updated 4 years ago