jeffbryner / NBDServer
Network Block Device Server for windows with a DFIR/forensic focus.
☆97Updated 7 years ago
Related projects ⓘ
Alternatives and complementary repositories for NBDServer
- Library and tools to access the Volume Shadow Snapshot (VSS) format☆110Updated 3 months ago
- An NTFS journal parser☆82Updated 8 years ago
- Digital Forensics Windows Registry (dfWinReg)☆49Updated last month
- Recurse through a registry, identifying values with large data -- a registry malware hunter☆44Updated 8 years ago
- AuditParser☆58Updated 11 years ago
- SystemInspector is a script to pull a majority of the security-relevant files and settings from a system.☆17Updated 6 years ago
- Unpack MIME attachments from a file and check them against virustotal.com☆45Updated 8 years ago
- Decode security descriptors in $Secure on NTFS☆20Updated 2 years ago
- Evidence Fetcher (efetch) is a web-based file explorer, viewer, and analyzer.☆37Updated 4 years ago
- Python unbup script for McAfee .bup files (with some additional fun features). This script is fully implemented in python it's not just a…☆36Updated 6 years ago
- Carves EXEs from given data files, using intelligent carving based upon PE headers☆36Updated 7 years ago
- Extract common Windows artifacts from source images and VSCs☆65Updated 3 years ago
- A Powershell script for frequency analysis of separated values data files.☆17Updated 10 years ago
- Checks with NSRL RDS servers looking for for hash matches☆111Updated 3 years ago
- Yara rules for malware families seen as part of targeted threats project☆134Updated 8 years ago
- A boot record parser that identifies known good signatures for MBR, VBR and IPL.☆97Updated 6 years ago
- Automated memory forensics analysis☆32Updated 5 years ago
- openioc_scan Volatility Framework plugin☆42Updated 8 years ago
- Yet another registry parser☆130Updated 2 years ago
- Tool to parse SRU database☆24Updated 6 years ago
- Open source Python library for NTFS analysis☆80Updated 6 years ago
- A Windows Event Processing Utility☆46Updated 6 years ago
- Python script to parse the NTFS USN Journal☆107Updated 2 years ago
- Queries to parse sysmon event log file with microsoft logparser☆56Updated 9 years ago
- This is a copy of the Registry Decoder repository from Google Code.☆27Updated 9 years ago
- Python library for parsing AccessData AD1 images☆29Updated last year
- Active Directory Group Policy analyzer☆96Updated 10 years ago