janstarke / evtxviewLinks
evtxview is a GUI viewer for Microsoft Windows evtx files (Windows event logs). I'm hacking this tiny tool because I need such a tool in most forensic investigations.
☆16Updated 4 years ago
Alternatives and similar repositories for evtxview
Users that are interested in evtxview are comparing it to the libraries listed below
Sorting:
- Dump certificates from PE files in different formats☆38Updated last year
- A console debugger using DbgX and Terminal.Gui☆30Updated 3 years ago
- ☆29Updated 2 years ago
- A modified fork of Be.HexEditor for use in debug tools☆15Updated 3 years ago
- Set of scripts for performance investigations on Windows.☆25Updated 3 months ago
- Brute Force password recovery for exported Windows PFX certificates☆17Updated 8 years ago
- Diff tool for comparing symbols in PDB files☆84Updated 5 years ago
- Auditing Hooks for https://github.com/jborean93/PSDetour☆13Updated 6 months ago
- ☆44Updated 2 years ago
- Lnk file parser☆90Updated 5 months ago
- ComPower is a Windows PowerShell module to work with the Component Object Model (COM).☆31Updated 10 years ago
- ☆19Updated 2 years ago
- Win32 memory leak detector with ETW☆47Updated 7 years ago
- PerfMonX is an enhanced Performance Monitor tool☆44Updated 7 years ago
- Library to process OLE compound file format. This is a work in progress and was initially written for jumplist parsing (for which it does…☆19Updated 9 months ago
- WPF helper library☆14Updated 6 years ago
- INF Studio for easier working with driver installation files☆38Updated last year
- .NET wrapper for dbghelp.dll☆21Updated 6 years ago
- Automatic/Custom Destinations & LNK (MS-SHLLINK) Browser☆38Updated last year
- Managed wrappers around the Windows API and some Native API☆36Updated 7 years ago
- Portable Executable parsing library, used by PEExplorer. Also available as a nuget package☆36Updated 7 years ago
- Viewing NTFS alternate streams in files☆33Updated 8 years ago
- Security testing tools for Windows sandboxing technologies☆174Updated 6 months ago
- An attempt to create a friendly version of WinDbg☆105Updated 7 years ago
- Grepify the GUI Regex Text Scanner for Code Reviewers☆23Updated 12 years ago
- extract and parse WEVT_TEMPLATEs from PE files☆18Updated last year
- An IDA plugin to deal with Event Tracing for Windows (ETW)☆55Updated 3 years ago
- PowerShell PE Parser☆64Updated last year
- WinDbg installer/updater☆42Updated 2 years ago
- An example pattern in C# for using WMI to monitor process creation and termination events.☆53Updated 7 years ago