libyal / libfwsi
Library to access the Windows Shell Item format
☆67Updated 3 months ago
Related projects ⓘ
Alternatives and complementary repositories for libfwsi
- Windows Prefetch parser. Supports all known versions from Windows XP to Windows 10.☆105Updated 3 months ago
- Cross-platform, open-source shellbag parser☆149Updated last year
- Lnk file parser☆78Updated 2 months ago
- Library and tools to access the Windows Prefetch File (SCCA) format.☆71Updated 2 months ago
- ☆15Updated 2 months ago
- Tool to extract the $UsnJrnl from an NTFS volume☆105Updated 5 years ago
- An NTFS journal parser☆82Updated 8 years ago
- Win 10/11 related research☆177Updated 10 months ago
- Extension blocks as found in ShellBags and other places in the Registry☆23Updated 2 months ago
- Automatic and Custom Destinations jump list parser with Windows 10 support☆74Updated last year
- Yet another registry parser☆129Updated 2 years ago
- Windows registry samples☆23Updated 5 years ago
- Registry Explorer bookmark definitions☆41Updated last year
- Parser for $UsnJrnl on NTFS☆108Updated last year
- Windows Registry Knowledge Base☆162Updated last month
- A repo that contains a recursive dump from the ROOT key of every Windows Registry hive (using KAPE) from a vanilla (clean) install of eve…☆43Updated last year
- Windows 10 (v1803+) ActivitiesCache.db parsers (SQLite, PowerShell, .EXE)☆177Updated last year
- Full featured, offline Registry parser in C#☆221Updated 2 months ago
- Yet another library library (and tools)☆201Updated last month
- Parser for $LogFile on NTFS☆189Updated 11 months ago
- Parse Microsoft shim databases☆28Updated 2 months ago
- Tool to monitor WMI activity on Windows☆198Updated 4 years ago
- Emulates the Sysinternals Autoruns tool, but for DFIR purposes e.g. multi user processing☆53Updated 5 years ago
- Extract common Windows artifacts from source images and VSCs☆65Updated 3 years ago
- Library and tools to access the Windows NT Registry File (REGF) format☆107Updated 2 months ago
- Windows link file (shortcuts) examiner☆67Updated 5 months ago
- FileInsight-plugins: decoding toolbox of McAfee FileInsight hex editor for malware analysis☆156Updated this week
- ☆19Updated 2 years ago
- Decode security descriptors in $Secure on NTFS☆20Updated 2 years ago