$MFT Record Viewer
☆24Nov 9, 2022Updated 3 years ago
Alternatives and similar repositories for MFT_Record_Viewer
Users that are interested in MFT_Record_Viewer are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Windows 10 Live Information viewer☆38Jan 27, 2022Updated 4 years ago
- $MFT directory tree reconstruction & FILE record info☆326Oct 7, 2024Updated last year
- Library to handle the files in zff format (file format to store and handle forensic acquisitions).☆21Mar 9, 2026Updated 2 weeks ago
- A modified fork of Be.HexEditor for use in debug tools☆15Jan 5, 2022Updated 4 years ago
- Windows.EDB Browser☆60Mar 6, 2023Updated 3 years ago
- Evtx Log (xml) Browser☆56Mar 12, 2023Updated 3 years ago
- From 2011: Quickly search for files in NTFS volumes parsing the Master File Table (MFT). A decent amount of how NTFS and MFT work was pai…☆29Oct 14, 2019Updated 6 years ago
- RegFineViewer is an utility to visualize and navigate easily the Windows Registry☆18Jan 20, 2021Updated 5 years ago
- Web app built to allow digital forensic professionals to search for the forensic tools that will parse artifacts from various apps.☆18Apr 30, 2025Updated 10 months ago
- Vagrant Files to create a Virtualbox VM for Malware Analysis☆13Jun 1, 2021Updated 4 years ago
- ☆18Mar 26, 2025Updated 11 months ago
- Active Directory Group Policy Preferences cpassword cracker/decrypter.☆24Apr 14, 2021Updated 4 years ago
- A repository of output using KAPE (!EZParser Module) for various publicly available forensic images!☆17Aug 31, 2024Updated last year
- A PowerShell module for querying the National Vulnerability Database☆25May 2, 2024Updated last year
- PowerShell scripts to aid investigators when utilizing O365 and Magnet Axiom.☆12Aug 26, 2024Updated last year
- Build a domain with three quick PowerShell scripts!☆29Jun 3, 2020Updated 5 years ago
- ☆40Aug 27, 2021Updated 4 years ago
- A batch script that checks Windows 11 readiness on your PC☆20Aug 16, 2023Updated 2 years ago
- Crowdstrike Falcon Host script for iterating through instances to get alert and other relevant data☆13Jul 16, 2019Updated 6 years ago
- A Python Typer-based CLI tool to generate fake data for Azure AD. AzDummy also uses Rich for some dope console output.☆13Apr 27, 2021Updated 4 years ago
- Python based Office Macro Generator. Also does rudamentary obfuscation.☆12Jun 6, 2016Updated 9 years ago
- An efficient tool for search files, directories, and alternate data streams directly from NTFS image files.☆28Mar 12, 2026Updated last week
- Import python libraries over HTTP☆13Oct 28, 2024Updated last year
- libdt is part of the "Huorong eXtendible Stream Scan Engine" project copyright by Huorong Borui (Beijing) Technology Co., Ltd.☆14Aug 17, 2015Updated 10 years ago
- ☆13Apr 30, 2020Updated 5 years ago
- A WDM Windows driver to issue IO to storage devices with asynchronous multithreaded processing☆21Aug 28, 2016Updated 9 years ago
- PoC for hiding data within $MFT☆12Aug 14, 2014Updated 11 years ago
- Formely KMon, a Windows Kernel Driver designed to prevent malware attacks by monitoring the creation of registry keys in common autorun l…☆21Feb 15, 2014Updated 12 years ago
- A small tool to easily mount APFS image on macOS for forensics.☆16Jul 30, 2020Updated 5 years ago
- A tool for fetching DFIR and other GitHub tools.☆26Aug 2, 2025Updated 7 months ago
- ☆29Aug 9, 2016Updated 9 years ago
- ☆17Jan 21, 2026Updated 2 months ago
- Notes from my "Implementing a Kick-Butt Training Program: Blue Team GO!" talk☆14Mar 4, 2019Updated 7 years ago
- System Security Project☆13Feb 28, 2017Updated 9 years ago
- Forensics tool for NTFS (parser, mft, bitlocker, deleted files)☆601Jul 23, 2023Updated 2 years ago
- x64dbg plugin to bypass Themida 3.1.x+ Anti-Debug, VM Detection & Monitoring Software☆19Aug 3, 2023Updated 2 years ago
- a GUI Interface for DFIR Open Source Tools☆10Jun 16, 2015Updated 10 years ago
- A repo for centralizing ongoing research on the new Windows 10/11 DFIR artifact, EventTranscript.db.☆44Jul 18, 2022Updated 3 years ago
- Windows 10 (v1803+) ActivitiesCache.db parsers (SQLite, PowerShell, .EXE)☆196Feb 16, 2023Updated 3 years ago