Utility to retrieve the Master File Table (MFT) from a live running NTFS volume and send it to a netcat listener.
☆41Oct 9, 2014Updated 11 years ago
Alternatives and similar repositories for pyMFTGrabber
Users that are interested in pyMFTGrabber are comparing it to the libraries listed below
Sorting:
- Log Examination Tool☆27Oct 11, 2016Updated 9 years ago
- misc scripts☆35Oct 23, 2018Updated 7 years ago
- Home to the ActorTrackr source code☆24Jun 21, 2017Updated 8 years ago
- Python script to parse the NTFS USN Journal☆116Jul 15, 2022Updated 3 years ago
- Public Maltego Transforms☆24May 24, 2017Updated 8 years ago
- analyzeMFT.py is designed to fully parse the MFT file from an NTFS filesystem and present the results as accurately as possible in multip…☆527Aug 13, 2025Updated 7 months ago
- Windows DLL Loading Utility☆12Jun 11, 2020Updated 5 years ago
- ☆21Aug 14, 2025Updated 7 months ago
- Carve files for MFT entries (eg. blkls output or memory dumps). Recovers filenames (long & short), timestamps ($STD & $FN) and data if re…☆22Jun 3, 2019Updated 6 years ago
- Python bindings for Yeti's API☆19Sep 12, 2023Updated 2 years ago
- Tool suite for inspecting NTFS artifacts.☆226Nov 1, 2023Updated 2 years ago
- A tool to generate yara signatures from function blocks☆19Dec 8, 2014Updated 11 years ago
- ☆14Jan 3, 2024Updated 2 years ago
- ☆16May 9, 2016Updated 9 years ago
- IOC-EDT is an open source web based tool for creating indicators of compromise in the OpenIOC (http://www.openioc.org) format.☆18May 10, 2014Updated 11 years ago
- An efficient tool for extracting files, directories, and alternate data streams directly from NTFS image files.☆22Mar 12, 2026Updated last week
- CryptnetURLCacheParser is a tool to parse CryptAPI cache files☆21Aug 3, 2024Updated last year
- Providing timelines based on OSINT Reports☆31Jun 21, 2023Updated 2 years ago
- Slack Parser is a script to parse slack database and extract user-data, chat history, workspace information☆16Feb 21, 2021Updated 5 years ago
- A book about how to conduct digital forensic investigations with free and open source tools.☆12Apr 30, 2014Updated 11 years ago
- iOS forensics utility☆13May 8, 2018Updated 7 years ago
- ReviveIT (revit) is a proof of concept file recovery tool (carver)☆13Dec 3, 2020Updated 5 years ago
- Automatically exported from code.google.com/p/fuzzdb☆14Jun 23, 2015Updated 10 years ago
- Single server/laptop grade file-observatory☆10Mar 30, 2023Updated 2 years ago
- Parse Windows Prefetch files: Supports XP - Windows 10 Prefetch files☆122May 29, 2024Updated last year
- Python tools for IOC (Indicator of Compromise) handling☆96Nov 25, 2021Updated 4 years ago
- Command line $MFT record decoder☆12May 20, 2017Updated 8 years ago
- Library for Windows XML Event Log (EVTX) data types☆18Dec 17, 2025Updated 3 months ago
- ☆10Apr 28, 2025Updated 10 months ago
- A tool for detecting viruses and NSFW material in WARC files☆18Dec 16, 2025Updated 3 months ago
- Pool Overflow in OpenVpn NDIS TAP Driver☆17Nov 3, 2015Updated 10 years ago
- A persistent repository for PRONOM Research Week activities☆12May 26, 2021Updated 4 years ago
- Simple tool to automate adding shellcode to PE files☆49Apr 10, 2018Updated 7 years ago
- Django app for managing PREMIS Events☆14Mar 9, 2026Updated last week
- Recurse through a registry, identifying values with large data -- a registry malware hunter☆45Sep 12, 2016Updated 9 years ago
- An NTFS journal parser☆80Mar 3, 2016Updated 10 years ago
- This software (prototype) extracts values of Excel spreadsheet properties and calculates a tentative spreadsheet complexity assessment ba…☆13Dec 13, 2022Updated 3 years ago
- Windows kernel vulnerability in win32k.sys Driver☆35Dec 6, 2015Updated 10 years ago
- A warehouse for your malware☆136Nov 21, 2025Updated 4 months ago