libyal / libesedb
Library and tools to access the Extensible Storage Engine (ESE) Database File (EDB) format.
☆341Updated 3 months ago
Related projects ⓘ
Alternatives and complementary repositories for libesedb
- ☆417Updated last year
- Active Directory forensic framework☆319Updated 2 years ago
- Commandline low level file extractor for NTFS☆274Updated 5 years ago
- Remote Command Executor: A OSS replacement for PsExec and RunAs - or Telnet without having to install a server. Take your pick :)☆336Updated 7 years ago
- Volatility plugins developed and maintained by the community☆342Updated 3 years ago
- Executes PowerShell from an unmanaged process☆476Updated 8 years ago
- Parse evtx files and detect use of the DanderSpritz eventlogedit module☆147Updated 6 years ago
- A YARA-integrated process denial framework for Windows☆396Updated 4 years ago
- Library and tools to access the Windows XML Event Log (EVTX) format☆190Updated last month
- PowerShell Obfuscation Detection Framework☆725Updated 11 months ago
- Full featured, offline Registry parser in C#☆223Updated last week
- Log newly created WMI consumers and processes to the Windows Application event log☆124Updated 6 years ago
- Replay RDP traffic from PCAP☆187Updated 5 years ago
- Not PowerShell☆444Updated 8 years ago
- ☆273Updated last year
- ☆506Updated 3 years ago
- A JavaScript and VBScript Based Empire Launcher, which runs within their own embedded PowerShell Host.☆319Updated 7 years ago
- This repo is for WMIOps, a powershell script which uses WMI for various purposes across a network.☆381Updated 4 months ago
- Pure Python parser for Windows Registry hives.☆426Updated 11 months ago
- A PoC WMI backdoor presented at Black Hat 2015☆270Updated 9 years ago
- A list of ways to execute code on Windows using legitimate Windows tools☆303Updated 5 years ago
- Remote execution, like PsExec☆542Updated 3 years ago
- Some PowerShell Stuff☆280Updated 2 years ago
- analyzeMFT.py is designed to fully parse the MFT file from an NTFS filesystem and present the results as accurately as possible in multip…☆446Updated last month
- random powershell goodness☆441Updated 5 years ago
- Reconstruct process trees from event logs☆146Updated 4 years ago
- Netview enumerates systems using WinAPI calls☆289Updated 2 years ago
- Extract $MFT record info and log it to a csv file.☆259Updated last month
- ☆213Updated 6 years ago
- Windows registry file format specification☆325Updated 6 years ago