Powerful commandline $MFT record editor.
☆25Aug 15, 2015Updated 10 years ago
Alternatives and similar repositories for PowerMft
Users that are interested in PowerMft are comparing it to the libraries listed below
Sorting:
- Command line $MFT record decoder☆12May 20, 2017Updated 8 years ago
- Decode security descriptors in $Secure on NTFS☆22Feb 24, 2022Updated 4 years ago
- Extract files off NTFS☆22Nov 1, 2014Updated 11 years ago
- ForGe Forensic test image generator☆34Mar 19, 2015Updated 11 years ago
- NTFS parser, plus linking capabilites between MFT LogFile and UsnJrnl☆38Aug 23, 2016Updated 9 years ago
- Carve $MFT records from a chunk of data (for instance a memory dump)☆16Aug 21, 2016Updated 9 years ago
- Tool to parse SRU database☆25Mar 1, 2018Updated 8 years ago
- SysScout is a fully encapsulated script that quickly and easily pulls local machine information from Linux-Based systems. A simple, easy…☆13Oct 20, 2017Updated 8 years ago
- Carve Windows Prefetch files from arbitrary binary data☆16Jun 11, 2017Updated 8 years ago
- Commandline low level file extractor for NTFS☆313Jul 30, 2019Updated 6 years ago
- PoC for hiding data within $MFT☆12Aug 14, 2014Updated 11 years ago
- Binaries for the log2timeline projects and dependencies☆40Feb 8, 2026Updated last month
- Parse Manifest.mbdb files from iTunes backup directories☆20Jun 29, 2017Updated 8 years ago
- recover deleted information from sqlite files.☆65Jun 17, 2016Updated 9 years ago
- Encase Script to parse harddrive for MFT data☆16Jun 17, 2016Updated 9 years ago
- Parser for Sdba memory pool tags☆21Jul 16, 2021Updated 4 years ago
- Tool to extract the $UsnJrnl from an NTFS volume☆109Jul 30, 2019Updated 6 years ago
- Carve NTFS USN records from binary data☆27May 21, 2017Updated 8 years ago
- VMware Snapshot Forensic Comparison Scripts☆25Mar 19, 2013Updated 13 years ago
- Library for Object Linking and Embedding (OLE) data types☆12Nov 27, 2025Updated 3 months ago
- Extract $MFT record info and log it to a csv file.☆288Oct 7, 2024Updated last year
- Creates an ATT&CK Navigator map of an Adversary Emulation Plan☆17Sep 4, 2021Updated 4 years ago
- LISP Evaluator for FreeBASIC. An embedded LISP interpreter written entirely in FreeBASIC for use with FreeBASIC applications.☆11Nov 20, 2017Updated 8 years ago
- Python based Office Macro Generator. Also does rudamentary obfuscation.☆12Jun 6, 2016Updated 9 years ago
- libdt is part of the "Huorong eXtendible Stream Scan Engine" project copyright by Huorong Borui (Beijing) Technology Co., Ltd.☆14Aug 17, 2015Updated 10 years ago
- Emulates the Sysinternals Autoruns tool, but for DFIR purposes e.g. multi user processing☆55May 18, 2019Updated 6 years ago
- Registry timestamp manipulation☆18Feb 26, 2014Updated 12 years ago
- A simple code for detects Host header vulnerability☆12Feb 18, 2020Updated 6 years ago
- Discover USB device history for a specific user☆23Dec 28, 2015Updated 10 years ago
- IR remote control for my Car PC. Emulates keyboard and mouse USB HID Combo device.☆10Jan 30, 2016Updated 10 years ago
- Crack base64(sha256(username)) hash from Microsoft Event ID 1029☆24Aug 4, 2023Updated 2 years ago
- System Security Project☆13Feb 28, 2017Updated 9 years ago
- Shell script to automate running the Nmap smb-security-mode.nse or RunFinger.py by lgandx and parse results into counts and lists of host…☆14Nov 3, 2017Updated 8 years ago
- A DFVFS Backed Forensic Viewer☆42Apr 13, 2020Updated 5 years ago
- ☆12Dec 16, 2016Updated 9 years ago
- Small scripts and POCs related to digital forensics☆18Nov 1, 2022Updated 3 years ago
- APFS filesystem format for Kaitai Struct☆81Apr 20, 2022Updated 3 years ago
- Experimental Sony ARW format parser.☆13Sep 7, 2018Updated 7 years ago
- Windows privileges add to the complexity of Windows user permissions. Each additional user added to a group could lead to a domain compro…☆10Mar 2, 2018Updated 8 years ago