janstarke / evtxviewLinks
evtxview is a GUI viewer for Microsoft Windows evtx files (Windows event logs). I'm hacking this tiny tool because I need such a tool in most forensic investigations.
☆15Updated 5 years ago
Alternatives and similar repositories for evtxview
Users that are interested in evtxview are comparing it to the libraries listed below
Sorting:
- Dump certificates from PE files in different formats☆38Updated 2 years ago
- Automatic/Custom Destinations & LNK (MS-SHLLINK) Browser☆41Updated last year
- ☆30Updated 3 years ago
- A modified fork of Be.HexEditor for use in debug tools☆14Updated 4 years ago
- Auditing Hooks for https://github.com/jborean93/PSDetour☆13Updated 9 months ago
- PowerShell PE Parser☆63Updated last year
- ComPower is a Windows PowerShell module to work with the Component Object Model (COM).☆32Updated 11 years ago
- Library to process OLE compound file format. This is a work in progress and was initially written for jumplist parsing (for which it does…☆19Updated last year
- Lnk file parser☆90Updated 8 months ago
- ☆44Updated 2 years ago
- Brute Force password recovery for exported Windows PFX certificates☆17Updated 9 years ago
- Analyzers for Portable Executable anomalies and other malware behavior.☆33Updated this week
- Set of scripts for performance investigations on Windows.☆32Updated last month
- Windows Detour Hooking in PowerShell☆82Updated last month
- A console debugger using DbgX and Terminal.Gui☆30Updated 3 years ago
- Windows.EDB Browser☆60Updated 2 years ago
- .NET wrapper for dbghelp.dll☆21Updated 6 years ago
- ☆76Updated this week
- version 0.5.8☆17Updated 4 years ago
- A C# (.NET 6) tool to compare the file signature of files recursively and inform the user of matches and mismatches☆16Updated last year
- Extension blocks as found in ShellBags and other places in the Registry☆25Updated last year
- ☆19Updated 2 years ago
- Automatic and Custom Destinations jump list parser with Windows 10 support☆115Updated 4 months ago
- Autopsy Module to analyze Registry Hives☆15Updated 3 years ago
- Cmdlets for capturing Windows Events☆14Updated 3 years ago
- extract and parse WEVT_TEMPLATEs from PE files☆18Updated 2 years ago
- DiscUtils is a .NET library to read and write ISO files and Virtual Machine disk files (VHD, VDI, XVA, VMDK, etc). DiscUtils is developed…☆19Updated 10 years ago
- AppLocker baseline configuration with the AaronLocker module. Used for testing with Windows 10, Intune etc.☆20Updated 2 months ago
- PowerShell script that decrypts password entries from a Passwordstate server.☆26Updated 3 years ago
- Diff tool for comparing symbols in PDB files☆84Updated 5 years ago