EricZimmerman / evtxLinks
C# based evtx parser with lots of extras
☆337Updated 3 months ago
Alternatives and similar repositories for evtx
Users that are interested in evtx are comparing it to the libraries listed below
Sorting:
- Parses $MFT from NTFS file systems☆281Updated 7 months ago
- Parses amcache.hve files, but with a twist!☆144Updated 10 months ago
- Event Tracing For Windows (ETW) Resources☆409Updated last month
- Get all my software☆179Updated 6 months ago
- Sysmon EDR POC Build within Powershell to prove ability.☆225Updated 4 years ago
- OneDriveExplorer is a command line and GUI based application for reconstructing the folder structure of OneDrive from the <UserCid>.dat a…☆222Updated last month
- A repo that contains recursive directory listings (using PowerShell) of a vanilla (clean) install of every Windows OS version to compare …☆183Updated last month
- $MFT directory tree reconstruction & FILE record info