kacos2000 / WinHex_Templates
X-Ways Forensic/ WinHex templates
☆41Updated 2 years ago
Related projects: ⓘ
- Library and tools to access the Windows NT Registry File (REGF) format☆103Updated last month
- Windows 右键“发送到”接力;分组“发送到”;用指定程序打开;启动器;组织你的工具箱。 Send what sent to me to my 'sendto' for Windows; open with specified program; group sendto…☆22Updated 9 months ago
- Windows Registry Knowledge Base☆158Updated 5 months ago
- Library and tools to access the Windows Prefetch File (SCCA) format.☆70Updated last month
- ☆19Updated 2 years ago
- Parse Microsoft shim databases☆28Updated 2 weeks ago
- MFT parser☆58Updated 6 months ago
- Windows.EDB Browser☆53Updated last year
- ☆59Updated 2 months ago
- ☆53Updated 3 years ago
- Mount VSCs with ease!☆14Updated last year
- Collection of tips, tools, arsenal and techniques I've learned during RE and other CyberSecStuff☆53Updated 4 months ago
- Extension blocks as found in ShellBags and other places in the Registry☆23Updated 2 weeks ago
- Command line utility for copying files on NTFS using low level disk access☆32Updated 5 months ago
- An efficient tool for search files, directories, and alternate data streams directly from NTFS image files.☆19Updated 6 months ago
- A repo that contains a recursive dump from the ROOT key of every Windows Registry hive (using KAPE) from a vanilla (clean) install of eve…☆44Updated last year
- A collection of free miscellaneous Windows tools☆118Updated 3 weeks ago
- Browse Windows Prefetch versions: 17,23,26,30v1/2 & some of SuperFetch .7db/.db's☆39Updated 7 months ago
- An efficient tool for extracting files, directories, and alternate data streams directly from NTFS image files.☆17Updated 6 months ago
- Provide an easy way to use C Run-time Library from Windows Kernel exported from ntdll.dll in your user-mode applications☆51Updated last month
- ☆33Updated last year
- AppCompatCache (shimcache) parser. Supports Windows 7 (x86 and x64), Windows 8.x, and Windows 10☆107Updated 2 weeks ago
- Tool to extract the $UsnJrnl from an NTFS volume☆104Updated 5 years ago
- Automatic/Custom Destinations & LNK (MS-SHLLINK) Browser☆30Updated 6 months ago
- Lnk file parser☆78Updated 2 weeks ago
- NTFS parser, plus linking capabilites between MFT LogFile and UsnJrnl☆36Updated 8 years ago
- Native Python3 bindings for @horsicq's Detect-It-Easy☆40Updated 3 weeks ago
- Parses RecentFileCacheParser.bcf files☆24Updated 2 weeks ago
- volatility explorer☆90Updated 3 years ago
- VMDK Forensic Artifact Extractor (VFAE) is windows based tool written in C++ that extracts files with a known location from VMDK images r…☆15Updated 9 years ago