Wrapper for TSK (Sleuth Kit) Bindings
☆12Jan 10, 2023Updated 3 years ago
Alternatives and similar repositories for libtsk-rs
Users that are interested in libtsk-rs are comparing it to the libraries listed below
Sorting:
- Manage Your Large Team of Consultants☆11Sep 18, 2025Updated 6 months ago
- Safe Rust API to libesedb☆12Sep 10, 2025Updated 6 months ago
- Windows file metadata / forensic tool.☆18Oct 12, 2025Updated 5 months ago
- Parsers for common structures across windows formats.☆12Aug 23, 2023Updated 2 years ago
- Rust crate for accessing keys, values, and data stored in Windows hive (registry) files.☆52Jan 21, 2025Updated last year
- USN to JSON☆22Apr 4, 2020Updated 5 years ago
- Python bindings for https://github.com/omerbenamram/evtx/☆55Jan 3, 2026Updated 2 months ago
- LNK to JSON☆14Mar 7, 2019Updated 7 years ago
- File Capability Extractor☆14Jul 12, 2025Updated 8 months ago
- lnk_parser is a full rust implementation to parse windows LNK files☆23Feb 17, 2026Updated last month
- A document tagging library☆33Mar 27, 2025Updated 11 months ago
- Scanner for certain IoCs☆11Jan 29, 2025Updated last year
- Tool for analysis of Windows Prefetch files☆26Nov 11, 2018Updated 7 years ago
- Remotely collect linux live forensics artifacts.☆14Jul 8, 2022Updated 3 years ago
- Memory Scaner☆65Sep 9, 2022Updated 3 years ago
- extract and parse WEVT_TEMPLATEs from PE files☆18Dec 30, 2023Updated 2 years ago
- my MSTICpy practice and custom tools repository☆11Apr 23, 2025Updated 10 months ago
- Automatically exported from code.google.com/p/mac-osx-forensics☆28Jan 12, 2016Updated 10 years ago
- Winterfell hunt is a python script to perform auto threat hunting for malicious activities in windows OS based on collected data by winte…☆15Jul 23, 2020Updated 5 years ago
- Get the process name or process id on windows☆20Jun 1, 2025Updated 9 months ago
- Forensic framework to build tools that can be reused in multiple projects without changing anything☆31Updated this week
- A Windows registry file parser written in Rust☆41Oct 30, 2025Updated 4 months ago
- Backstage Parser☆33Jun 23, 2022Updated 3 years ago
- http://moaistory.blogspot.com/2016/08/ie10analyzer.html☆19Jul 20, 2024Updated last year
- Recover event log entries from an image by heurisitically looking for record structures.☆26Oct 9, 2015Updated 10 years ago
- Help deobfuscate VBScript☆18Jul 1, 2022Updated 3 years ago
- A library for fast parse & import of Windows Master File Table($MFT) into Elasticsearch.☆12Jun 23, 2025Updated 8 months ago
- Rhaegal is a tool written in Python 3 used to scan Windows Event Logs for suspicious logs. Rhaegal uses custom rule format to detect sus…☆43Sep 21, 2023Updated 2 years ago
- An efficient tool for extracting files, directories, and alternate data streams directly from NTFS image files.☆22Mar 12, 2026Updated last week
- Library to handle the files in zff format (file format to store and handle forensic acquisitions).☆21Mar 9, 2026Updated last week
- An informational repo about hunting for adversaries in your IT environment.☆14Apr 10, 2017Updated 8 years ago
- Pure Rust fuzzy hash implementation☆22Mar 13, 2023Updated 3 years ago
- This script is made to collect the most valiable artifacts for foreniscs or incident reponse investigation rather than imaging the whole …☆210Oct 19, 2020Updated 5 years ago
- CLI tool to compute the TypeRefHash for .NET binaries.☆19Nov 10, 2021Updated 4 years ago
- macOS triage is a python script to collect various macOS logs, artifacts, and other data.☆25Mar 25, 2021Updated 4 years ago
- Repo with supporting material for the talk titled "Cracking the Beacon: Automating the extraction of implant configurations"☆11Feb 6, 2025Updated last year
- Discover USB device history for a specific user☆23Dec 28, 2015Updated 10 years ago
- A parser for the MFT (Master File Table) format☆157Jan 3, 2026Updated 2 months ago
- Tool to parse SRU database☆25Mar 1, 2018Updated 8 years ago