libyal / libfwsi
Library to access the Windows Shell Item format
☆69Updated 10 months ago
Alternatives and similar repositories for libfwsi
Users that are interested in libfwsi are comparing it to the libraries listed below
Sorting:
- Lnk file parser☆87Updated 3 months ago
- ☆18Updated 4 months ago
- Cross-platform, open-source shellbag parser☆149Updated 2 years ago
- Library and tools to access the Windows Prefetch File (SCCA) format.☆73Updated 4 months ago
- Yet another registry parser☆132Updated 3 years ago
- Registry Explorer bookmark definitions☆42Updated 4 months ago
- An NTFS journal parser☆82Updated 9 years ago
- Decode security descriptors in $Secure on NTFS☆20Updated 3 years ago
- Windows Prefetch parser. Supports all known versions from Windows XP to Windows 10.☆113Updated 4 months ago
- Full featured, offline Registry parser in C#☆229Updated 4 months ago
- Windows 10 (v1803+) ActivitiesCache.db parsers (SQLite, PowerShell, .EXE)☆189Updated 2 years ago
- Analysis and manipulation of extended attribute ($EA) on NTFS☆38Updated 9 years ago
- Library and tools to access the Windows NT Registry File (REGF) format☆118Updated 8 months ago
- ☆66Updated last week
- Windows Registry Knowledge Base☆173Updated 7 months ago
- Parses the WMI object database....looking for persistence☆31Updated 5 years ago
- Parser for $LogFile on NTFS☆194Updated last year
- Extensible Storage Engine (ESE) Database File Knowledge Base☆43Updated 7 months ago
- Extension blocks as found in ShellBags and other places in the Registry☆24Updated 4 months ago
- FileInsight-plugins: decoding toolbox of McAfee FileInsight hex editor for malware analysis☆161Updated 5 months ago
- $MFT parser (from live systems or a copy of the $MFT) and raw file copy utility☆36Updated 10 months ago
- Tool suite for inspecting NTFS artifacts.☆221Updated last year
- BCD is a module to interact with boot configuration data (BCD) either locally or remotely using the ROOT/WMI:Bcd* WMI classes. The functi…☆61Updated 4 years ago
- Windows registry samples☆23Updated 6 years ago
- Parser for $UsnJrnl on NTFS☆110Updated 2 years ago
- Emulates the Sysinternals Autoruns tool, but for DFIR purposes e.g. multi user processing☆55Updated 6 years ago
- Tool to extract the $UsnJrnl from an NTFS volume☆106Updated 5 years ago
- Python library for parsing AccessData AD1 images☆32Updated last year
- Parse Microsoft shim databases☆30Updated 4 months ago
- AFF4 Standard Documents☆28Updated 3 years ago