Library and tools to access the Volume Shadow Snapshot (VSS) format
☆114Dec 20, 2025Updated 3 months ago
Alternatives and similar repositories for libvshadow
Users that are interested in libvshadow are comparing it to the libraries listed below
Sorting:
- An advanced parser for INDX records☆29Aug 7, 2019Updated 6 years ago
- It is based on bulk_extractor (https://github.com/simsong/bulk_extractor) and add scanners for record carving☆42Apr 23, 2020Updated 5 years ago
- Library and tools to access the Extended File System☆18Feb 1, 2026Updated last month
- ☆16Apr 16, 2017Updated 8 years ago
- Library and tools to access the Master Boot Record (MBR) volume system format☆14Dec 21, 2025Updated 2 months ago
- Carves and recreates VSS catalog and store from Windows disk image.☆100Jan 24, 2023Updated 3 years ago
- Extract compressed memory pages from page-aligned data☆47Sep 25, 2018Updated 7 years ago
- Windows registry samples☆24Nov 18, 2018Updated 7 years ago
- Page File analysis tools.☆131Dec 3, 2015Updated 10 years ago
- Memory Baseliner is a script that can compare two windows memory images or perform frequency of occurrence / data stacking analysis on mu…☆56Jul 2, 2023Updated 2 years ago
- A better strings utility!☆149Feb 8, 2026Updated last month
- Library and tools to access the Windows (Vista/7) Explorer thumbnail cache database format (thumbcache.db)☆17Dec 3, 2025Updated 3 months ago
- Library and tools to access the GUID Partition Table (GPT) volume system format☆11Dec 20, 2025Updated 3 months ago
- ReviveIT (revit) is a proof of concept file recovery tool (carver)☆13Dec 3, 2020Updated 5 years ago
- "Evolving AppCompat/AmCache data analysis beyond grep"☆209Sep 15, 2021Updated 4 years ago
- Library and tools to access the Windows SuperFetch database format☆13Nov 29, 2025Updated 3 months ago
- Library and tools to access the Mac OS Hierarchical File System (HFS)☆36Jan 31, 2026Updated last month
- Decode security descriptors in $Secure on NTFS☆22Feb 24, 2022Updated 4 years ago
- Parser for $LogFile on NTFS☆215Jun 1, 2025Updated 9 months ago
- Library and tools to access the Windows Hibernation File (hiberfil.sys) format☆13Dec 20, 2025Updated 3 months ago
- EVTXtract recovers and reconstructs fragments of EVTX log files from raw binary data, including unallocated space and memory images.☆209Mar 12, 2025Updated last year
- NTFS file system specimens☆13Jul 3, 2023Updated 2 years ago
- Super timeline all the things☆2,034Feb 10, 2026Updated last month
- ☆432May 3, 2023Updated 2 years ago
- AFF is an open and extensible file format to store disk images and associated metadata.☆91Sep 8, 2025Updated 6 months ago
- NTFS parser, plus linking capabilites between MFT LogFile and UsnJrnl☆38Aug 23, 2016Updated 9 years ago
- Tool suite for inspecting NTFS artifacts.☆226Nov 1, 2023Updated 2 years ago
- AppCompatCache (shimcache) parser. Supports Windows 7 (x86 and x64), Windows 8.x, and Windows 10, and Windows 11☆129Jan 12, 2025Updated last year
- Tool to extract the $UsnJrnl from an NTFS volume☆109Jul 30, 2019Updated 6 years ago
- A Powershell incident response framework☆1,640Nov 22, 2022Updated 3 years ago
- Digital Forensics Virtual File System (dfVFS)☆219Feb 15, 2026Updated last month
- Python bindings for The Sleuth Kit (libtsk)☆112Nov 21, 2025Updated 3 months ago
- Assorted classes and methods for indexing reports and retrieving information from an elastic index☆21Jul 5, 2016Updated 9 years ago
- Automating forensic data extraction, reduction, and overall triage of cold disk and memory images.☆21Mar 12, 2019Updated 7 years ago
- Scripts and tools created for appx analysis talk (Magnet summit 2019)☆19Feb 26, 2024Updated 2 years ago
- Command line $MFT record decoder☆12May 20, 2017Updated 8 years ago
- Library for Object Linking and Embedding (OLE) data types☆12Nov 27, 2025Updated 3 months ago
- Library and tools to access the OLE 2 Compound File (OLECF) format☆74Dec 21, 2025Updated 2 months ago
- Volatility plugins created by the author☆44Oct 2, 2015Updated 10 years ago