libyal / libolecf
Library and tools to access the OLE 2 Compound File (OLECF) format
☆69Updated 9 months ago
Alternatives and similar repositories for libolecf:
Users that are interested in libolecf are comparing it to the libraries listed below
- Library and tools to access the Windows NT Registry File (REGF) format☆118Updated 8 months ago
- Library and tools to access the Windows Prefetch File (SCCA) format.☆73Updated 4 months ago
- Yet another library library (and tools)☆207Updated 4 months ago
- Library and tools to access the Windows New Technology File System (NTFS)☆207Updated 10 months ago
- Open source implementations of Microsoft compression algorithms☆209Updated 4 years ago
- Lnk file parser☆86Updated 3 months ago
- Named pipe I/O ETW provider for Windows☆70Updated 4 years ago
- Library and tools to access the Windows Event Log (EVT) format☆59Updated 10 months ago
- Library and tools to access the Windows Shortcut File (LNK) format☆203Updated 6 months ago
- Windows registry file format specification☆337Updated 6 years ago
- Win32 Console Documentation -- in particular, console/standard handles and CreateProcess inheritance☆111Updated last year
- File and libmagic for Windows☆113Updated 4 years ago
- A simple header file to read Microsoft compound file with minimal efforts.☆84Updated 3 weeks ago
- Module to generate and verify PE signatures☆50Updated last month
- A cross-platform library for verifying Authenticode signatures☆149Updated 2 months ago
- windows registry hive extraction library. PLEASE DO NOT USE GITHUB FOR ISSUES OR PULL REQUESTS. See the website for how to file a bug or…☆134Updated last week
- An NTFS journal parser☆82Updated 9 years ago
- Analysis and manipulation of extended attribute ($EA) on NTFS☆38Updated 9 years ago
- .NET wrapper for libyara built in C++ CLI used to easily incorporate yara into .NET projects☆54Updated 9 months ago
- Library and tools to access the Microsoft Internet Explorer (MSIE) Cache File (index.dat) files☆16Updated 9 months ago
- NTFS parser, plus linking capabilites between MFT LogFile and UsnJrnl☆37Updated 8 years ago
- PE file manipulation library.☆63Updated 5 years ago
- Library and tools to access the Master Boot Record (MBR) volume system format☆13Updated 10 months ago
- An example sandbox using AppContainer (Windows 8+)☆137Updated 5 years ago
- extract and parse WEVT_TEMPLATEs from PE files☆18Updated last year
- Library and tools to access the Volume Shadow Snapshot (VSS) format☆111Updated 8 months ago
- Library and tools to access the Windows XML Event Log (EVTX) format☆200Updated 7 months ago
- Library and tools to access the executable (EXE) format☆42Updated 10 months ago
- Extract files from NTFS Volume☆32Updated 3 years ago
- See your trace statements in Sysinternals Process Monitor☆87Updated 9 years ago