Velocidex / go-eseLinks
Go implementation of an Extensible Storage Engine parser
☆30Updated 4 months ago
Alternatives and similar repositories for go-ese
Users that are interested in go-ese are comparing it to the libraries listed below
Sorting:
- ☆33Updated 3 years ago
- Simple PowerShell script to enable process scanning with Yara.☆95Updated 2 years ago
- a tiny program to consume from ETW providers for research☆49Updated 6 months ago
- Hunt for SQLite files used by various applications☆26Updated this week
- Manipulate timestamps on NTFS☆51Updated 10 years ago
- ShellSweeping the evil.☆53Updated last year
- PS-TrustedDocuments: PowerShell script to handle information on trusted documents for Microsoft Office☆35Updated 2 years ago
- A set of tools for collecting forensic information☆26Updated 5 years ago
- Windows.EDB Browser☆57Updated 2 years ago
- Epimitheus is a tool that uses graphical database Neo4j for Windows Events visualization.☆19Updated 3 years ago
- Powershell Event Tracing Toolbox☆75Updated 3 years ago
- Parser for Windows PowerShell script block logs☆13Updated 6 months ago
- ☆19Updated 6 months ago
- SysInternals' Process Monitor filters repository - collected from various places and made up by myself. To be used for quick Behavioral a…☆67Updated 3 years ago
- Visual Studio Code Microsoft Sysinternal Sysmon configuration file extension.☆53Updated 2 years ago
- A Dissect module implementing a parser for Microsofts Extensible Storage Engine Database (ESEDB), used for example in Active Directory, E…☆20Updated last month
- Leghorn code for PKI abuse☆32Updated 4 years ago
- This repository aims to collect and document indicators from the different C2's listed in the C2-Matrix☆73Updated 3 years ago
- Evtx Log (xml) Browser☆56Updated 2 years ago
- A golang implementation of a prefetch parser.☆20Updated last month
- ☆10Updated last year
- Repository containing malware analysis filters for the Windows SysInternals' - Process Monitor tool☆18Updated 4 years ago
- Yara rules☆22Updated 2 years ago
- Generate YARA rules for OOXML documents.☆38Updated 2 years ago
- A powershell parser for https://github.com/ufrisk/MemProcFS☆44Updated 4 years ago
- C# User Simulation☆32Updated 2 years ago
- ☆34Updated 2 years ago
- This is a repo for fetching Applocker event log by parsing the win-event log☆31Updated 2 years ago
- General Content☆26Updated last year
- Create a cool process tree like https://twitter.com/ACEResponder.☆35Updated 2 years ago