EricZimmerman / AppCompatCacheParser
AppCompatCache (shimcache) parser. Supports Windows 7 (x86 and x64), Windows 8.x, and Windows 10
☆110Updated 2 weeks ago
Related projects ⓘ
Alternatives and complementary repositories for AppCompatCacheParser
- Parses amcache.hve files, but with a twist!☆120Updated 2 months ago
- Parses RecentFileCacheParser.bcf files☆25Updated 2 months ago
- Command line access to the Registry☆132Updated 2 weeks ago
- ☆60Updated 2 weeks ago
- ☆294Updated 4 years ago
- Script for parsing Symantec Endpoint Protection logs, VBNs, and ccSubSDK database.☆63Updated last year
- Windows Prefetch parser. Supports all known versions from Windows XP to Windows 10.☆106Updated 3 months ago
- A repository that maps API calls to Sysmon Event ID's.☆116Updated 2 years ago
- C# based evtx parser with lots of extras☆282Updated 2 months ago
- MFT parser☆62Updated 8 months ago
- Parser for $UsnJrnl on NTFS☆108Updated last year
- ☆19Updated 2 years ago
- Stand-alone parser for User Access Logging from Server 2012 and newer systems☆71Updated 10 months ago
- Cobalt Strike Beacon configuration extractor and parser.☆145Updated 3 years ago
- Memory Baseliner is a script that can compare two windows memory images or perform frequency of occurrence / data stacking analysis on mu…☆49Updated last year
- HXTool is an extended user interface for the FireEye HX Endpoint product. HXTool can be installed on a dedicated server or on your physic…☆79Updated 4 months ago
- Signature engine for all your logs☆161Updated last year
- Windows Registry Knowledge Base☆162Updated last month
- ☆37Updated 2 months ago
- YARA rule analyzer to improve rule quality and performance☆93Updated 11 months ago
- ☆61Updated last month
- Parses $MFT from NTFS file systems☆202Updated this week
- Extract BITS jobs from QMGR queue and store them as CSV records☆74Updated 4 months ago
- Dump quarantined files from Windows Defender☆56Updated 2 years ago
- Prefetch Explorer Command Line☆224Updated 2 months ago
- SysmonX - An Augmented Drop-In Replacement of Sysmon☆210Updated 5 years ago
- A library for fast parse & import of Windows Eventlogs into Elasticsearch.☆82Updated 4 months ago
- A better strings utility!☆120Updated last year
- Parser for $LogFile on NTFS☆190Updated 11 months ago
- Recycle bin artifact parser☆36Updated 2 months ago