libyal / libfwsiLinks
Library to access the Windows Shell Item format
☆72Updated last year
Alternatives and similar repositories for libfwsi
Users that are interested in libfwsi are comparing it to the libraries listed below
Sorting:
- Lnk file parser☆88Updated 2 months ago
- Win 10/11 related research☆190Updated last year
- Analysis and manipulation of extended attribute ($EA) on NTFS☆38Updated 10 years ago
- Windows Registry Knowledge Base☆177Updated 9 months ago
- Windows Prefetch parser. Supports all known versions from Windows XP to Windows 10.☆114Updated 6 months ago
- Windows 10 (v1803+) ActivitiesCache.db parsers (SQLite, PowerShell, .EXE)☆189Updated 2 years ago
- Enhanced version of the GFlags tool☆84Updated 6 years ago
- ☆20Updated 6 months ago
- Library and tools to access the Windows NT Registry File (REGF) format☆124Updated 11 months ago
- Expand compressed files from WinSxS folder☆159Updated 3 weeks ago
- Windows registry file format specification☆341Updated 6 years ago
- Full featured, offline Registry parser in C#☆231Updated 3 weeks ago
- Tool to monitor WMI activity on Windows☆288Updated 4 years ago
- A set of tools to retrieve and parse TCG measured boot logs. Microsoft refers to these as Windows Boot Confirguration Logs (WBCL). In ord…☆60Updated 7 years ago
- A collection of free miscellaneous Windows tools☆135Updated last week
- BCD is a module to interact with boot configuration data (BCD) either locally or remotely using the ROOT/WMI:Bcd* WMI classes. The functi…☆61Updated 4 years ago
- Yet another library library (and tools)☆211Updated 7 months ago
- The content of this repository aims to assist efforts on analysing inner working principles, functionalities, and properties of the Micro…☆151Updated 5 years ago
- Library and tools to access the Windows Prefetch File (SCCA) format.☆76Updated 7 months ago
- Parse Microsoft shim databases☆30Updated 6 months ago
- Extensible Storage Engine (ESE) Database File Knowledge Base☆43Updated 9 months ago
- Library and tools to access the Windows Shortcut File (LNK) format☆205Updated 9 months ago
- Decode security descriptors in $Secure on NTFS☆20Updated 3 years ago
- A PowerShell module to assist in parsing and managing catalog files.☆22Updated 8 years ago
- This is a fork of Regshot (original found at https://sourceforge.net/projects/regshot/) with very enhanced functionality.☆79Updated 4 years ago
- $MFT Record Viewer☆22Updated 2 years ago
- Module to provide PowerShell functions that abstract Win32 API functions☆248Updated last year
- Parser for $LogFile on NTFS☆199Updated 2 months ago
- Cross-platform, open-source shellbag parser☆151Updated 2 years ago
- Tool to extract the $UsnJrnl from an NTFS volume☆108Updated 6 years ago