kacos2000 / Win10
Win 10/11 related research
☆183Updated last year
Alternatives and similar repositories for Win10:
Users that are interested in Win10 are comparing it to the libraries listed below
- Windows 10 (v1803+) ActivitiesCache.db parsers (SQLite, PowerShell, .EXE)☆181Updated 2 years ago
- Windows Registry Knowledge Base☆171Updated 4 months ago
- ☆63Updated last month
- Windows Prefetch parser. Supports all known versions from Windows XP to Windows 10.☆111Updated last month
- Software downloads☆96Updated last month
- Command line access to the Registry☆135Updated last month
- Automatic and Custom Destinations jump list parser with Windows 10 support☆81Updated last month
- $MFT directory tree reconstruction & FILE record info☆298Updated 4 months ago
- http://moaistory.blogspot.com/2018/10/winsearchdbanalyzer.html☆121Updated 7 months ago
- Tool suite for inspecting NTFS artifacts.☆218Updated last year
- A repo that contains a recursive dump from the ROOT key of every Windows Registry hive (using KAPE) from a vanilla (clean) install of eve…☆45Updated last year
- Tools from WFA 4/e, timeline tools, etc.☆134Updated 11 months ago
- Full featured, offline Registry parser in C#☆226Updated last month
- Extract common Windows artifacts from source images and VSCs☆65Updated 3 years ago
- MFT parser☆65Updated 2 weeks ago
- AppCompatCache (shimcache) parser. Supports Windows 7 (x86 and x64), Windows 8.x, and Windows 10☆114Updated last month
- Documentation repository☆44Updated 5 months ago
- Parser for $UsnJrnl on NTFS☆109Updated 2 years ago
- An NTFS journal parser☆82Updated 8 years ago
- Tool to extract the $UsnJrnl from an NTFS volume☆106Updated 5 years ago
- Parser for $LogFile on NTFS☆191Updated last year
- Yet another registry parser☆130Updated 2 years ago
- Parses $MFT from NTFS file systems☆219Updated this week
- Parses the WMI object database....looking for persistence☆31Updated 5 years ago
- This is a GUI (for Windows 64 bit) for a procedure to virtualize your EWF(E01), DD (raw), AFF disk image file without converting it, dire…☆54Updated 5 years ago
- Emulates the Sysinternals Autoruns tool, but for DFIR purposes e.g. multi user processing☆55Updated 5 years ago
- Registry Explorer bookmark definitions☆41Updated 2 months ago
- Windows registry file format specification☆337Updated 6 years ago
- ☆16Updated last month
- A repo that contains recursive directory listings (using PowerShell) of a vanilla (clean) install of every Windows OS version to compare …☆153Updated 2 months ago