Powerful commandline $MFT record editor.
☆25Aug 15, 2015Updated 10 years ago
Alternatives and similar repositories for PowerMft
Users that are interested in PowerMft are comparing it to the libraries listed below
Sorting:
- Command line $MFT record decoder☆12May 20, 2017Updated 8 years ago
- Decode security descriptors in $Secure on NTFS☆22Feb 24, 2022Updated 4 years ago
- Extract files off NTFS☆22Nov 1, 2014Updated 11 years ago
- Carve $MFT records from a chunk of data (for instance a memory dump)☆16Aug 21, 2016Updated 9 years ago
- ForGe Forensic test image generator☆34Mar 19, 2015Updated 10 years ago
- Makes files super hidden on NTFS☆19Aug 14, 2014Updated 11 years ago
- NTFS parser, plus linking capabilites between MFT LogFile and UsnJrnl☆38Aug 23, 2016Updated 9 years ago
- Small and highly portable detection tests.☆12Oct 12, 2017Updated 8 years ago
- Library for Object Linking and Embedding (OLE) data types☆12Nov 27, 2025Updated 3 months ago
- PoC for hiding data within $MFT☆12Aug 14, 2014Updated 11 years ago
- Tool to parse SRU database☆25Mar 1, 2018Updated 8 years ago
- Binaries for the log2timeline projects and dependencies☆40Feb 8, 2026Updated 3 weeks ago
- SysScout is a fully encapsulated script that quickly and easily pulls local machine information from Linux-Based systems. A simple, easy…☆13Oct 20, 2017Updated 8 years ago
- Creates an ATT&CK Navigator map of an Adversary Emulation Plan☆17Sep 4, 2021Updated 4 years ago
- ☆12Dec 16, 2016Updated 9 years ago
- Parser for Sdba memory pool tags☆21Jul 16, 2021Updated 4 years ago
- Encase Script to parse harddrive for MFT data☆16Jun 17, 2016Updated 9 years ago
- Registry timestamp manipulation☆17Feb 26, 2014Updated 12 years ago
- Extract $MFT record info and log it to a csv file.☆286Oct 7, 2024Updated last year
- VMware Snapshot Forensic Comparison Scripts☆25Mar 19, 2013Updated 12 years ago
- Emulates the Sysinternals Autoruns tool, but for DFIR purposes e.g. multi user processing☆55May 18, 2019Updated 6 years ago
- Cumulonimbus-UAL_Extractor is a PowerShell based tool created by the Tesorion CERT team to help gather the Unified Audit Logging out of a…☆21Oct 25, 2023Updated 2 years ago
- Parse Manifest.mbdb files from iTunes backup directories☆20Jun 29, 2017Updated 8 years ago
- Library and tools to access the Microsoft Internet Explorer (MSIE) Cache File (index.dat) files☆17Dec 19, 2025Updated 2 months ago
- Crack base64(sha256(username)) hash from Microsoft Event ID 1029☆23Aug 4, 2023Updated 2 years ago
- Workflows for Shuffle☆24Oct 26, 2022Updated 3 years ago
- MasterParser is a simple, all-in-one, digital forensics artifact parser☆24Jul 9, 2021Updated 4 years ago
- Discover USB device history for a specific user☆23Dec 28, 2015Updated 10 years ago
- This repository is a collection of EnScript code samples for use in the OpenText Endpoint Forensic and OpenText Endpoint Investigator app…☆54Jul 14, 2025Updated 7 months ago
- Tool to extract the $UsnJrnl from an NTFS volume☆109Jul 30, 2019Updated 6 years ago
- sholes (Motorola Droid CDMA) device tree for CM9/ICS☆12Sep 7, 2012Updated 13 years ago
- Threat hunting repo for my independent study on threat hunting with OSQuery☆27Jan 16, 2018Updated 8 years ago
- An open source project aimed to replicate the Windows SIFT Machine and tools used during SANS Courses minus any payware software.☆25Oct 18, 2023Updated 2 years ago
- An NTFS file parser in Go☆72Mar 22, 2025Updated 11 months ago
- Carve NTFS USN records from binary data☆27May 21, 2017Updated 8 years ago
- ☆30Nov 15, 2018Updated 7 years ago
- This repository contains additional files mentioned in the blog post☆22Feb 26, 2019Updated 7 years ago
- ☆11Feb 28, 2022Updated 4 years ago
- Resources for HFS+ Forensics☆37Nov 15, 2015Updated 10 years ago