jschicht / EaTools
Analysis and manipulation of extended attribute ($EA) on NTFS
☆39Updated 9 years ago
Related projects ⓘ
Alternatives and complementary repositories for EaTools
- A set of tools to retrieve and parse TCG measured boot logs. Microsoft refers to these as Windows Boot Confirguration Logs (WBCL). In ord…☆53Updated 6 years ago
- Parse Microsoft shim databases☆28Updated 2 months ago
- A collection of free miscellaneous Windows tools☆122Updated 2 months ago
- Named pipe I/O ETW provider for Windows☆66Updated 4 years ago
- WNF Utilities 4 Newbies (WNFUN)☆91Updated 5 years ago
- Library and tools to access the Windows Prefetch File (SCCA) format.☆71Updated 2 months ago
- The content of this repository aims to assist efforts on analysing inner working principles, functionalities, and properties of the Micro…☆150Updated 4 years ago
- Run executables in an AppContainer☆116Updated 5 years ago
- Expand compressed files from WinSxS folder☆146Updated 4 months ago
- Extension blocks as found in ShellBags and other places in the Registry☆23Updated 2 months ago
- BCD is a module to interact with boot configuration data (BCD) either locally or remotely using the ROOT/WMI:Bcd* WMI classes. The functi…☆60Updated 4 years ago
- Metadata hash incorporating the Rich Header for robustness against packing and other malware tricks☆61Updated 3 years ago
- extract and parse WEVT_TEMPLATEs from PE files☆18Updated 10 months ago
- Enhanced version of the GFlags tool☆82Updated 5 years ago
- Lnk file parser☆78Updated 2 months ago
- This tool is the result of a reverse engineering process of the Windows service called SysMain. Time to interact with the prefetch files …☆30Updated 4 years ago
- Scripts to prepare Windows system for debugging.☆30Updated 3 years ago
- Faster version of `symchk /om` for generating PDB manifests of offline machines☆19Updated 3 years ago
- A GUI version of the classic PoolMon tool☆110Updated 6 years ago
- FileInsight-plugins: decoding toolbox of McAfee FileInsight hex editor for malware analysis☆156Updated this week
- ☆60Updated this week
- A PowerShell module to assist in parsing and managing catalog files.☆19Updated 7 years ago
- CallMon is an experimental system call monitoring tool that works on Windows 10 versions 2004+ using PsAltSystemCallHandlers☆129Updated 4 years ago
- Library and tools to access the Windows NT Registry File (REGF) format☆107Updated 2 months ago
- All TMF files that I extracted from Microsoft PDBs.☆12Updated 5 years ago
- A local copy of Alex Ionescu's seemingly abandoned native-nt-toolkit project containing knowledge inherited from the ReactOS project.☆53Updated 5 years ago
- DotNext 2019 St. Petersburg Talk Demos☆36Updated 5 years ago
- Diff tool for comparing symbols in PDB files☆83Updated 4 years ago
- AppContainer and LPAC (Less Privileged AppContainer) Launcher with Capabilities☆57Updated last month