RobinDavid / pyADS
Python module to manipulate NTFS Alternate Data Stream (ADS) in Python
☆56Updated 5 years ago
Related projects ⓘ
Alternatives and complementary repositories for pyADS
- Utility to retrieve the Master File Table (MFT) from a live running NTFS volume and send it to a netcat listener.☆40Updated 10 years ago
- Powerful commandline $MFT record editor.☆23Updated 9 years ago
- ☆18Updated 11 years ago
- Python script to parse the NTFS USN Journal☆107Updated 2 years ago
- Capture-Py is a malware analysis tool that makes a copy of any files deleted or modified in a given directory and sub-directories. It was…☆23Updated 7 years ago
- Windows link file (shortcuts) examiner☆67Updated 5 months ago
- $MFT parser (from live systems or a copy of the $MFT) and raw file copy utility☆36Updated 4 months ago
- X-Ways C# X-Tension API☆15Updated 11 years ago
- Open source Python library for NTFS analysis☆80Updated 6 years ago
- Windows Thingies in Python for live use.☆24Updated 5 years ago
- ☆54Updated 4 years ago
- Static analysis tools for Microsoft Office Open XML files and documents☆68Updated 7 years ago
- Proof of concept VBA code to add to Normal.dot to put restrictions on Word☆41Updated 7 years ago
- Recurse through a registry, identifying values with large data -- a registry malware hunter☆44Updated 8 years ago
- Extract compressed memory pages from page-aligned data☆41Updated 6 years ago
- Tool suite for inspecting NTFS artifacts.☆216Updated last year
- threadmap plugin for Volatility Foundation☆27Updated 3 years ago
- Decode security descriptors in $Secure on NTFS☆20Updated 2 years ago
- Breaking the security of Microsoft's RMS☆53Updated 5 years ago
- All TMF files that I extracted from Microsoft PDBs.☆12Updated 5 years ago
- Basic demo for Hidden Treasure talk.☆49Updated 7 years ago
- ☆81Updated 5 years ago
- Parse Windows Prefetch files: Supports XP - Windows 10 Prefetch files☆115Updated 5 months ago
- s(4)u for Windows☆48Updated 3 years ago
- Windows Shortcut file (LNK) parser☆134Updated 2 years ago
- Recover event log entries from an image by heurisitically looking for record structures.☆27Updated 9 years ago
- Library and tools to access the Windows SuperFetch database format☆12Updated 4 months ago
- This project is a lightweight wrapper for interacting with WMI using python/ctypes☆37Updated 5 years ago