libyal / esedb-kbLinks
Extensible Storage Engine (ESE) Database File Knowledge Base
☆43Updated 9 months ago
Alternatives and similar repositories for esedb-kb
Users that are interested in esedb-kb are comparing it to the libraries listed below
Sorting:
- Event metadata collected across all manifest-based ETW providers on Window 10 1903☆31Updated 5 years ago
- All TMF files that I extracted from Microsoft PDBs.☆13Updated 6 years ago
- A PowerShell module to assist in parsing and managing catalog files.☆22Updated 8 years ago
- Windows Registry Knowledge Base☆176Updated 9 months ago
- Decode security descriptors in $Secure on NTFS☆20Updated 3 years ago
- Digital Forensics Windows Registry (dfWinReg)☆52Updated 6 months ago
- PowerShell Module for the Antimalware Scan Interface (AMSI)☆25Updated 8 years ago
- A set of tools to retrieve and parse TCG measured boot logs. Microsoft refers to these as Windows Boot Confirguration Logs (WBCL). In ord…☆59Updated 7 years ago
- Visual Studio Code Microsoft Sysinternal Sysmon configuration file extension.☆53Updated 2 years ago
- Active Directory Group Policy analyzer☆105Updated 11 years ago
- Windows Event Log Knowledge Base☆26Updated 9 months ago
- Library and tools to access the Microsoft Internet Explorer (MSIE) Cache File (index.dat) files☆16Updated 11 months ago
- Binary commandline executable to parse ETL files☆67Updated 7 years ago
- Windows registry samples☆23Updated 6 years ago
- Library and tools to access the Windows Prefetch File (SCCA) format.☆75Updated 6 months ago
- ☆18Updated 12 years ago
- PowerShell script useful for Incident Response and security/configuration baselines for Windows Vista and later☆20Updated 9 years ago
- Windows DPAPI laboratory☆93Updated 7 years ago
- Simple Windows Event Log Forwarder (SWELF). Its easy to use/simply works Log Forwarder and EVTX Parser. Almost in full release here at ht…☆24Updated 2 years ago
- Parses the WMI object database....looking for persistence☆32Updated 5 years ago
- Registry Explorer bookmark definitions☆43Updated 6 months ago
- Baseline Health Scripts☆10Updated 8 years ago
- PowerKrabsEtw is a PowerShell interface for doing real-time ETW tracing.☆103Updated 4 years ago
- A repo that contains a recursive dump from the ROOT key of every Windows Registry hive (using KAPE) from a vanilla (clean) install of eve…☆46Updated 2 years ago
- Repository containing malware analysis filters for the Windows SysInternals' - Process Monitor tool☆18Updated 4 years ago
- BCD is a module to interact with boot configuration data (BCD) either locally or remotely using the ROOT/WMI:Bcd* WMI classes. The functi…☆61Updated 4 years ago
- Library and tools to access the Windows SuperFetch database format☆12Updated last year
- Library and tools to access the Windows Event Log (EVT) format☆60Updated last year
- ☆19Updated 6 months ago
- Yet another registry parser☆132Updated 3 years ago