libyal / dtformats
Collection of data formats
☆163Updated last month
Related projects ⓘ
Alternatives and complementary repositories for dtformats
- A parser for Unified logging tracev3 files☆80Updated 10 months ago
- Forensic Artifact Collection Tool for macOS☆98Updated 2 months ago
- ☆212Updated this week
- Parser for OSX/iOS FSEvents Logs☆236Updated 8 months ago
- An AFF4 C++ implementation.☆188Updated last year
- Read and extract data from macOS spotlight databases☆104Updated last year
- Command line utility and Python package to ease the (un)mounting of forensic disk images☆120Updated last year
- Automatically exported from code.google.com/p/mac-osx-forensics☆27Updated 8 years ago
- A timestamp and date decoder written for python 3☆33Updated 3 months ago
- A command line tool for pstree-like output on macOS with additional pid capturing capabilities☆245Updated 2 months ago
- Presentation Archives for my macOS and iOS Related Research☆239Updated last month
- Mapping XProtect's obfuscated malware family names to common industry names.☆82Updated 6 months ago
- Windows registry file format specification☆325Updated 6 years ago
- The Python implementation of the AFF4 standard.☆45Updated 6 months ago
- A library to parse macOS FsEvents☆18Updated 2 years ago
- Scripts to parse various iOS sysdiagnose logs. Based upon the forensic research of Mattia Epifani, Heather Mahalik and Cheeky4n6monkey.☆169Updated 2 years ago
- Yet another registry parser☆130Updated 2 years ago
- File recovery for APFS☆159Updated 2 years ago
- Yet another library library (and tools)☆201Updated last month
- APFS filesystem format for Kaitai Struct☆81Updated 2 years ago
- Scripts to process macOS forensic artifacts☆181Updated 3 months ago
- An NTFS/FAT parser for digital forensics & incident response☆192Updated 2 weeks ago
- AFF4 Standard Documents☆26Updated 2 years ago
- DC3 SQLite Dissect☆54Updated 2 weeks ago
- Library and tools to access the Mac OS Hierarchical File System (HFS)☆34Updated 4 months ago
- Parser fo macOS/iOS FSEvents Logs☆26Updated 6 months ago
- This is a work-in-progress command line tool for reversing run-only AppleScripts. It will help parse the output of applescript-disassembl…☆64Updated 3 years ago
- macOS .DS_Store Parser☆61Updated 3 years ago
- ☆29Updated 4 years ago
- machofile is a module to parse Mach-O binary files☆48Updated 9 months ago