libyal / libregf
Library and tools to access the Windows NT Registry File (REGF) format
☆107Updated 3 months ago
Related projects ⓘ
Alternatives and complementary repositories for libregf
- Library and tools to access the Windows Prefetch File (SCCA) format.☆71Updated this week
- Windows Registry Knowledge Base☆162Updated last month
- Library and tools to access the Windows New Technology File System (NTFS)☆190Updated 4 months ago
- Tool suite for inspecting NTFS artifacts.☆216Updated last year
- NTFS parser, plus linking capabilites between MFT LogFile and UsnJrnl☆36Updated 8 years ago
- An NTFS journal parser☆82Updated 8 years ago
- Windows registry file format specification☆325Updated 6 years ago
- ☆60Updated 2 weeks ago
- A better strings utility!☆120Updated last year
- Parse Microsoft shim databases☆29Updated 2 months ago
- Windows Prefetch parser. Supports all known versions from Windows XP to Windows 10.☆106Updated 3 months ago
- FileInsight-plugins: decoding toolbox of McAfee FileInsight hex editor for malware analysis☆156Updated last week
- Named pipe I/O ETW provider for Windows☆67Updated 4 years ago
- Lnk file parser☆79Updated 2 months ago
- Python script to parse the NTFS USN Journal☆107Updated 2 years ago
- Parser for $UsnJrnl on NTFS☆108Updated last year
- Full featured, offline Registry parser in C#☆223Updated last week
- Enumerate Windows Defender threat families and dump their names according category☆86Updated 5 years ago
- Expand compressed files from WinSxS folder☆146Updated 4 months ago
- Command line access to the Registry☆132Updated 2 weeks ago
- MFT parser☆62Updated 8 months ago
- Parser for $LogFile on NTFS☆190Updated 11 months ago
- windows registry hive extraction library. PLEASE DO NOT USE GITHUB FOR ISSUES OR PULL REQUESTS. See the website for how to file a bug or…☆128Updated 3 weeks ago
- Open source implementations of Microsoft compression algorithms☆206Updated 4 years ago
- Pure Python parser for Application Compatibility Shim Databases (.sdb files)☆106Updated 3 years ago
- A local copy of Alex Ionescu's seemingly abandoned native-nt-toolkit project containing knowledge inherited from the ReactOS project.☆53Updated 5 years ago
- Windows registry samples☆23Updated 6 years ago
- Various Yara signatures (possibly to be included in a release later).☆85Updated 5 years ago
- .NET wrapper for libyara built in C++ CLI used to easily incorporate yara into .NET projects☆51Updated 3 months ago