libyal / libewf
Libewf is a library to access the Expert Witness Compression Format (EWF)
☆263Updated 3 weeks ago
Related projects: ⓘ
- Python bindings for The Sleuth Kit (libtsk)☆90Updated 5 months ago
- An AFF4 C++ implementation.☆187Updated last year
- Tool suite for inspecting NTFS artifacts.☆213Updated 10 months ago
- analyzeMFT.py is designed to fully parse the MFT file from an NTFS filesystem and present the results as accurately as possible in multip…☆429Updated this week
- Extract $MFT record info and log it to a csv file.☆254Updated 9 months ago
- Script for automating Linux memory capture and analysis☆263Updated 4 years ago
- Digital Forensics Virtual File System (dfVFS)☆202Updated 4 months ago
- An NTFS/FAT parser for digital forensics & incident response☆189Updated last year
- Parser for $LogFile on NTFS☆184Updated 9 months ago
- Yet another library library (and tools)☆201Updated last week
- ☆375Updated this week
- SIFT☆484Updated 7 months ago
- Volatility plugins developed and maintained by the community☆339Updated 3 years ago
- Autopsy Python Plugins☆333Updated 6 months ago
- Command line utility and Python package to ease the (un)mounting of forensic disk images☆116Updated last year
- The kernel patch and userspace tools to enable Linux software write blocking☆133Updated 4 years ago
- DC3 Malware Configuration Parser (DC3-MWCP) is a framework for parsing configuration information from malware. The information extracted …☆293Updated 3 months ago
- Library and tools to access the Volume Shadow Snapshot (VSS) format☆109Updated last month
- Yara integrated software to handle archive file data.☆296Updated 2 years ago
- Commandline low level file extractor for NTFS☆272Updated 5 years ago
- Regipy is an os independent python library for parsing offline registry hives☆240Updated 3 weeks ago
- Pure Python parser for Windows Registry hives.☆425Updated 9 months ago
- This is the development tree. Production downloads are at:☆1,079Updated 4 months ago
- Yara Rule Analyzer and Statistics☆356Updated last year
- Volatility profiles for Linux and Mac OS X☆317Updated last year
- Parser for $UsnJrnl on NTFS☆103Updated last year
- Repository of modules and signatures contributed by the community☆322Updated last year
- ☆415Updated last year
- A better strings utility!☆119Updated last year
- A framework for orchestrating forensic collection, processing and data export☆290Updated this week