libyal / esedb-kbLinks
Extensible Storage Engine (ESE) Database File Knowledge Base
☆46Updated 2 weeks ago
Alternatives and similar repositories for esedb-kb
Users that are interested in esedb-kb are comparing it to the libraries listed below
Sorting:
- A PowerShell module to assist in parsing and managing catalog files.☆22Updated 8 years ago
- Windows Registry Knowledge Base☆191Updated 2 weeks ago
- Registry Explorer bookmark definitions☆43Updated 11 months ago
- Windows registry samples☆24Updated 7 years ago
- Parses the WMI object database....looking for persistence☆34Updated 6 years ago
- A repo that contains a recursive dump from the ROOT key of every Windows Registry hive (using KAPE) from a vanilla (clean) install of eve…☆49Updated last month
- Event metadata collected across all manifest-based ETW providers on Window 10 1903☆31Updated 6 years ago
- Binary commandline executable to parse ETL files☆68Updated 7 years ago
- SysInternals' Process Monitor filters repository - collected from various places and made up by myself. To be used for quick Behavioral a…☆70Updated 4 years ago
- $MFT parser (from live systems or a copy of the $MFT) and raw file copy utility☆38Updated last year
- Windows 10 (v1803+) ActivitiesCache.db parsers (SQLite, PowerShell, .EXE)☆195Updated 2 years ago
- ☆71Updated 3 months ago
- Extension blocks as found in ShellBags and other places in the Registry☆25Updated 11 months ago
- Parse Microsoft shim databases☆31Updated 11 months ago
- Library and tools to access the Windows Prefetch File (SCCA) format.☆81Updated last week
- ☆18Updated 12 years ago
- A collection of Windows software baseline notes with corresponding Windows Defender Application Control (WDAC) policies☆63Updated last year
- Repository containing malware analysis filters for the Windows SysInternals' - Process Monitor tool☆20Updated 5 years ago
- Visual Studio Code Microsoft Sysinternal Sysmon configuration file extension.☆53Updated 2 years ago
- Trace ScriptBlock execution for powershell v2☆41Updated 5 years ago
- Script for parsing Symantec Endpoint Protection logs, VBNs, and ccSubSDK database.☆64Updated 2 years ago
- MFT parser☆74Updated 10 months ago
- Windows Prefetch parser. Supports all known versions from Windows XP to Windows 10.☆115Updated 11 months ago
- ☆94Updated 2 months ago
- Parser for $UsnJrnl on NTFS☆118Updated 3 years ago
- This tool is the result of a reverse engineering process of the Windows service called SysMain. Time to interact with the prefetch files …☆32Updated 5 years ago
- A better strings utility!☆141Updated 3 months ago
- Decode security descriptors in $Secure on NTFS☆21Updated 3 years ago
- Manipulate timestamps on NTFS☆53Updated 11 years ago
- Scripts and tools created for appx analysis talk (Magnet summit 2019)☆18Updated last year