EricZimmerman / RECmd
Command line access to the Registry
☆132Updated 3 weeks ago
Related projects ⓘ
Alternatives and complementary repositories for RECmd
- ☆60Updated this week
- Stand-alone parser for User Access Logging from Server 2012 and newer systems☆71Updated 10 months ago
- AppCompatCache (shimcache) parser. Supports Windows 7 (x86 and x64), Windows 8.x, and Windows 10☆110Updated 3 weeks ago
- MFT parser☆62Updated 8 months ago
- Registry Explorer bookmark definitions☆41Updated last year
- A better strings utility!☆120Updated last year
- Documentation repository☆43Updated 2 months ago
- ☆47Updated 3 weeks ago
- Script for parsing Symantec Endpoint Protection logs, VBNs, and ccSubSDK database.☆63Updated last year
- ☆37Updated 2 months ago
- Dump quarantined files from Windows Defender☆56Updated 2 years ago
- Get all my software☆143Updated 2 months ago
- Memory Baseliner is a script that can compare two windows memory images or perform frequency of occurrence / data stacking analysis on mu…☆49Updated last year
- Extract common Windows artifacts from source images and VSCs☆65Updated 3 years ago
- Extract BITS jobs from QMGR queue and store them as CSV records☆74Updated 4 months ago
- Parses amcache.hve files, but with a twist!☆121Updated 2 months ago
- ☆31Updated last month
- Parses the WMI object database....looking for persistence☆31Updated 4 years ago
- A repo that contains recursive directory listings (using PowerShell) of a vanilla (clean) install of every Windows OS version to compare …☆146Updated last month
- A modern Python-3-based alternative to RegRipper☆187Updated 2 weeks ago
- A script that updates KAPE (using Get-KAPEUpdate.ps1) as well as EZ Tools (within .\KAPE\Modules\bin) and the ancillary files that enhanc…☆53Updated last year
- Windows Prefetch parser. Supports all known versions from Windows XP to Windows 10.☆106Updated 3 months ago
- A parser of Windows Defender's DetectionHistory forensic artifact, containing substantial info about quarantined files and executables.☆109Updated 2 years ago
- Parses $MFT from NTFS file systems☆202Updated last week
- "Evolving AppCompat/AmCache data analysis beyond grep"☆197Updated 3 years ago
- Software downloads☆93Updated 2 weeks ago
- Extension blocks as found in ShellBags and other places in the Registry☆23Updated 2 months ago
- HXTool is an extended user interface for the FireEye HX Endpoint product. HXTool can be installed on a dedicated server or on your physic…☆79Updated 4 months ago
- Invoke-LiveResponse☆145Updated 2 years ago
- Yet another registry parser☆130Updated 2 years ago