libyal / libfwsi
Library to access the Windows Shell Item format
☆68Updated 7 months ago
Alternatives and similar repositories for libfwsi:
Users that are interested in libfwsi are comparing it to the libraries listed below
- Tool suite for inspecting NTFS artifacts.☆219Updated last year
- Windows Prefetch parser. Supports all known versions from Windows XP to Windows 10.☆111Updated last month
- Cross-platform, open-source shellbag parser☆150Updated 2 years ago
- Lnk file parser☆81Updated last month
- Expand compressed files from WinSxS folder☆153Updated 8 months ago
- FileInsight-plugins: decoding toolbox of McAfee FileInsight hex editor for malware analysis☆159Updated 2 months ago
- Yet another library library (and tools)☆206Updated 2 months ago
- Yet another registry parser☆130Updated 2 years ago
- An NTFS journal parser☆82Updated 9 years ago
- Parser for $LogFile on NTFS☆192Updated last year
- Library and tools to access the Windows Prefetch File (SCCA) format.☆72Updated 2 months ago
- Extract $MFT record info and log it to a csv file.☆264Updated 4 months ago
- Windows 10 (v1803+) ActivitiesCache.db parsers (SQLite, PowerShell, .EXE)☆181Updated 2 years ago
- Windows Registry Knowledge Base☆171Updated 4 months ago
- Tool to extract the $UsnJrnl from an NTFS volume☆106Updated 5 years ago
- Decode security descriptors in $Secure on NTFS☆20Updated 3 years ago
- Win 10/11 related research☆184Updated last year
- Reconstruct process trees from event logs☆147Updated 4 years ago
- Various Yara signatures (possibly to be included in a release later).☆86Updated 5 years ago
- ☆17Updated last month
- Extract common Windows artifacts from source images and VSCs☆65Updated 3 years ago
- Full featured, offline Registry parser in C#☆226Updated last month
- Comae Hibernation File Decompressor☆144Updated last year
- A repo that contains a recursive dump from the ROOT key of every Windows Registry hive (using KAPE) from a vanilla (clean) install of eve…☆45Updated last year
- Parser for $UsnJrnl on NTFS☆109Updated 2 years ago
- A better strings utility!☆128Updated last month
- Registry Explorer bookmark definitions☆41Updated 2 months ago
- Digital Forensics Windows Registry (dfWinReg)☆49Updated 2 months ago
- Automatic and Custom Destinations jump list parser with Windows 10 support☆81Updated last month
- Parse Microsoft shim databases☆29Updated last month