An NTFS file parser in Go
☆72Mar 22, 2025Updated 11 months ago
Alternatives and similar repositories for go-ntfs
Users that are interested in go-ntfs are comparing it to the libraries listed below
Sorting:
- A Portable Executable parser for Golang☆48Nov 7, 2025Updated 4 months ago
- A golang implementation of a prefetch parser.☆20Oct 27, 2025Updated 4 months ago
- Golang Parser for Microsoft Event Logs☆105Nov 7, 2025Updated 4 months ago
- NTFS Master File Table (MFT) parser for Go.☆46Aug 21, 2024Updated last year
- A Golang Registry parser☆19Feb 3, 2025Updated last year
- A library implementing a generic SQL like query language.☆21Sep 15, 2025Updated 5 months ago
- Queries for parsed spotlight database in sqlite☆13Dec 29, 2020Updated 5 years ago
- PowerShell scripts to aid investigators when utilizing O365 and Magnet Axiom.☆12Aug 26, 2024Updated last year
- Parsers for common structures across windows formats.☆12Aug 23, 2023Updated 2 years ago
- 📚 A collection of tools and libraries to parse filesystems, archives and other data types☆22Oct 20, 2024Updated last year
- NTFS file system specimens☆13Jul 3, 2023Updated 2 years ago
- lnk_parser is a full rust implementation to parse windows LNK files☆23Feb 17, 2026Updated 2 weeks ago
- Windows registry samples☆24Nov 18, 2018Updated 7 years ago
- Publicly shareable windows event log message data☆28Nov 29, 2019Updated 6 years ago
- This package provides an S3 implementation for Go1.16 filesystem interface.☆13Apr 21, 2025Updated 10 months ago
- A Go implementation and parser for Sigma rules.☆95May 15, 2025Updated 9 months ago
- kaitaigo is a compiler and runtime to create Go parsers from Kaitai Struct files☆18Apr 20, 2022Updated 3 years ago
- iknowthis Linux SystemCall Fuzzer☆20Apr 18, 2019Updated 6 years ago
- Stand-alone parser for User Access Logging from Server 2012 and newer systems☆78Jan 9, 2024Updated 2 years ago
- Powershell Scripts to work on Crowdstrike Falcon that pull back raw data relevant to forensic investigation☆23Dec 18, 2024Updated last year
- Automating forensic data extraction, reduction, and overall triage of cold disk and memory images.☆21Mar 12, 2019Updated 6 years ago
- geolocate ip addresses in IIS logs☆20Jan 8, 2025Updated last year
- A clone of FD (File & Directory tool) by T.Shirai☆16Jan 29, 2014Updated 12 years ago
- ☆24Mar 12, 2025Updated 11 months ago
- Registry Explorer bookmark definitions☆44Dec 19, 2024Updated last year
- An NTFS/FAT parser for digital forensics & incident response☆220Oct 31, 2025Updated 4 months ago
- go package to chain fs.FS filesystems together (go1.16+)☆28Feb 23, 2023Updated 3 years ago
- ☆12Updated this week
- PoC for hiding data within $MFT☆12Aug 14, 2014Updated 11 years ago
- Mimikatz embedded as classes☆28Oct 25, 2021Updated 4 years ago
- A utility to force query DNS over DoH off of CloudFlare API when DNS block is in place☆10Aug 26, 2018Updated 7 years ago
- Repo with supporting material for the talk titled "Cracking the Beacon: Automating the extraction of implant configurations"☆11Feb 6, 2025Updated last year
- GUI for regripper☆11Mar 19, 2019Updated 6 years ago
- Powerful commandline $MFT record editor.☆25Aug 15, 2015Updated 10 years ago
- Go implementation of an Extensible Storage Engine parser☆32Feb 15, 2025Updated last year
- The Python implementation of the AFF4 standard.☆45Nov 13, 2025Updated 3 months ago
- NTFS Security Descriptor Stream ($Secure:$SDS) parser☆14Jan 9, 2023Updated 3 years ago
- This script will generate hashes (MD5, SHA1, SHA256), submit the MD5 to Virus Total, and produce a text file with the results.☆15Jul 13, 2023Updated 2 years ago
- Mount VSCs with ease!☆18Jan 22, 2025Updated last year