libyal / libesedb
Library and tools to access the Extensible Storage Engine (ESE) Database File (EDB) format.
☆344Updated 5 months ago
Alternatives and similar repositories for libesedb:
Users that are interested in libesedb are comparing it to the libraries listed below
- Commandline low level file extractor for NTFS☆277Updated 5 years ago
- Active Directory forensic framework☆322Updated 2 years ago
- Remote Command Executor: A OSS replacement for PsExec and RunAs - or Telnet without having to install a server. Take your pick :)☆342Updated 7 years ago
- ☆419Updated last year
- Executes PowerShell from an unmanaged process☆476Updated 8 years ago
- random powershell goodness☆441Updated last month
- ☆389Updated 4 years ago
- Library and tools to access the Windows XML Event Log (EVTX) format☆194Updated 3 months ago
- PowerShell module to check if a Windows binary (EXE/DLL) has been compiled with ASLR, DEP, SafeSEH, StrongNaming, and Authenticode.☆629Updated 5 months ago
- A PoC WMI backdoor presented at Black Hat 2015☆271Updated 9 years ago
- ☆274Updated last year
- A PowerShell Module Dedicated to Reverse Engineering☆865Updated 3 years ago
- This repo is for WMIOps, a powershell script which uses WMI for various purposes across a network.☆380Updated 6 months ago
- PowerShell Module with Security cmdlets for security work☆437Updated 4 years ago
- Replay RDP traffic from PCAP☆189Updated 5 years ago
- Remote execution, like PsExec☆546Updated 3 years ago
- Volatility plugins developed and maintained by the community☆351Updated 3 years ago
- Automatically exported from code.google.com/p/creddump☆247Updated 5 years ago
- PowerShell Remote Download Cradle Generator & Obfuscator☆824Updated 6 years ago
- PowerShell Obfuscation Detection Framework☆728Updated last year
- ☆507Updated 3 years ago
- Log newly created WMI consumers and processes to the Windows Application event log☆124Updated 6 years ago
- Easily define in-memory enums, structs, and Win32 functions in PowerShell☆218Updated 6 years ago
- ☆743Updated last year
- Netview enumerates systems using WinAPI calls☆292Updated 2 years ago
- Module to provide PowerShell functions that abstract Win32 API functions☆241Updated 7 months ago
- Allows you to quickly query a Windows machine for RAM artifacts☆218Updated 4 years ago
- Full featured, offline Registry parser in C#☆225Updated last week
- Not PowerShell☆444Updated 8 years ago