kacos2000 / WindowsTimeline
Windows 10 (v1803+) ActivitiesCache.db parsers (SQLite, PowerShell, .EXE)
☆177Updated last year
Related projects ⓘ
Alternatives and complementary repositories for WindowsTimeline
- Command line access to the Registry☆130Updated last week
- This is a set of tools for doing forensics analysis on Microsoft ESE databases.☆123Updated 2 years ago
- The Office 365 Extractor is a tool that allows for complete and reliable extraction of the Unified Audit Log (UAL)☆159Updated last year
- Get all my software☆141Updated last month
- Invoke-LiveResponse☆145Updated 2 years ago
- A parser of Windows Defender's DetectionHistory forensic artifact, containing substantial info about quarantined files and executables.☆109Updated 2 years ago
- A repo that contains recursive directory listings (using PowerShell) of a vanilla (clean) install of every Windows OS version to compare …☆145Updated last month
- Extract BITS jobs from QMGR queue and store them as CSV records☆74Updated 4 months ago
- AppCompatCache (shimcache) parser. Supports Windows 7 (x86 and x64), Windows 8.x, and Windows 10☆109Updated last week
- $MFT directory tree reconstruction & FILE record info☆292Updated last month
- ☆60Updated last week
- C# based evtx parser with lots of extras☆280Updated 2 months ago
- OneDriveExplorer is a command line and GUI based application for reconstructing the folder structure of OneDrive from the <UserCid>.dat a…☆181Updated last week
- Stand-alone parser for User Access Logging from Server 2012 and newer systems☆71Updated 10 months ago
- Yet another registry parser☆129Updated 2 years ago
- Documentation repository☆43Updated 2 months ago
- Win 10/11 related research☆177Updated 10 months ago
- A modern Python-3-based alternative to RegRipper☆187Updated this week
- ☆141Updated 5 months ago
- Registry Explorer bookmark definitions☆41Updated last year
- ☆36Updated 2 months ago
- A PowerShell incident response script for quick triage☆75Updated 2 years ago
- Extract common Windows artifacts from source images and VSCs☆65Updated 3 years ago
- Windows Registry Knowledge Base☆162Updated last month
- MFT parser☆61Updated 7 months ago
- This script is made to collect the most valiable artifacts for foreniscs or incident reponse investigation rather than imaging the whole …☆192Updated 4 years ago
- Script for parsing Symantec Endpoint Protection logs, VBNs, and ccSubSDK database.☆63Updated last year
- Parses $MFT from NTFS file systems☆198Updated last week
- A better strings utility!☆120Updated last year
- A repository that maps API calls to Sysmon Event ID's.☆116Updated last year