Utility to retrieve the Master File Table (MFT) from a live running NTFS volume and send it to a netcat listener.
☆41Oct 9, 2014Updated 11 years ago
Alternatives and similar repositories for pyMFTGrabber
Users that are interested in pyMFTGrabber are comparing it to the libraries listed below
Sorting:
- Log Examination Tool☆27Oct 11, 2016Updated 9 years ago
- Home to the ActorTrackr source code☆24Jun 21, 2017Updated 8 years ago
- ☆16May 9, 2016Updated 9 years ago
- An efficient tool for extracting files, directories, and alternate data streams directly from NTFS image files.☆22Feb 21, 2026Updated last week
- A tool to generate yara signatures from function blocks☆19Dec 8, 2014Updated 11 years ago
- analyzeMFT.py is designed to fully parse the MFT file from an NTFS filesystem and present the results as accurately as possible in multip…☆523Aug 13, 2025Updated 6 months ago
- Tool suite for inspecting NTFS artifacts.☆226Nov 1, 2023Updated 2 years ago
- IOC-EDT is an open source web based tool for creating indicators of compromise in the OpenIOC (http://www.openioc.org) format.☆18May 10, 2014Updated 11 years ago
- Library for Windows XML Event Log (EVTX) data types☆18Dec 17, 2025Updated 2 months ago
- Python script to parse the NTFS USN Journal☆115Jul 15, 2022Updated 3 years ago
- Pool Overflow in OpenVpn NDIS TAP Driver☆17Nov 3, 2015Updated 10 years ago
- Python bindings for Yeti's API☆19Sep 12, 2023Updated 2 years ago
- Windows kernel vulnerability in win32k.sys Driver☆35Dec 6, 2015Updated 10 years ago
- misc scripts☆35Oct 23, 2018Updated 7 years ago
- Python tools for IOC (Indicator of Compromise) handling☆96Nov 25, 2021Updated 4 years ago
- Decode security descriptors in $Secure on NTFS☆22Feb 24, 2022Updated 4 years ago
- Public Maltego Transforms☆24May 24, 2017Updated 8 years ago
- Generate RSA keys, encrypt and decrypt data☆24Apr 8, 2021Updated 4 years ago
- Windows Event Log Knowledge Base☆31Dec 23, 2025Updated 2 months ago
- Providing timelines based on OSINT Reports☆31Jun 21, 2023Updated 2 years ago
- Simple tool to automate adding shellcode to PE files☆49Apr 10, 2018Updated 7 years ago
- ☆24Feb 19, 2017Updated 9 years ago
- Assorted classes and methods for indexing reports and retrieving information from an elastic index☆21Jul 5, 2016Updated 9 years ago
- Python bindings for The Sleuth Kit (libtsk)☆112Nov 21, 2025Updated 3 months ago
- OpenHIPS prevents exploitation of Windows systems☆35Jan 7, 2013Updated 13 years ago
- FireEye Alert json files to MISP Malware information sharing plattform (Alpha)☆32Jun 11, 2017Updated 8 years ago
- cobalt strike stuff I have gathered from around github☆31May 5, 2017Updated 8 years ago
- Ping Exfiltration Command and Control (PiX-C2)☆32May 15, 2015Updated 10 years ago
- Make Windows LNK file with python (pylnk)☆64Jun 4, 2016Updated 9 years ago
- Open source Python library for NTFS analysis☆84Dec 22, 2017Updated 8 years ago
- 🔵 ethereum grid trading bot☆36Oct 10, 2025Updated 4 months ago
- VirusTotal Intelligence Notification Puller☆28Jun 29, 2016Updated 9 years ago
- Python script for extracting USB information from Windows registry hives☆128Aug 14, 2019Updated 6 years ago
- Compare multiple log formats against malware reputation lists.☆88Jul 27, 2017Updated 8 years ago
- An automated script that download potential exploit for linux kernel from exploitdb, and compile them automatically☆25Apr 30, 2016Updated 9 years ago
- Parse Windows Prefetch files: Supports XP - Windows 10 Prefetch files☆122May 29, 2024Updated last year
- Exploit WinIo - Vidix and Run Shellcode in Windows Kerne ( local Privilege escalation )☆28Aug 30, 2015Updated 10 years ago
- Network Block Device Server for windows with a DFIR/forensic focus.☆96Mar 31, 2017Updated 8 years ago
- CVE-2016-2776☆27Oct 3, 2016Updated 9 years ago