libyal / reviveit
ReviveIT (revit) is a proof of concept file recovery tool (carver)
☆12Updated 4 years ago
Alternatives and similar repositories for reviveit:
Users that are interested in reviveit are comparing it to the libraries listed below
- This is a copy of the Registry Decoder Live repository from Google Code☆9Updated 9 years ago
- Discover potential timestamps within the Windows Registry☆18Updated 10 years ago
- Library and tools to access the Windows Hibernation File (hiberfil.sys) format☆13Updated 8 months ago
- Server for receiving autorun data from the clients☆13Updated 7 years ago
- Working through Practical Malware Analysis from No Starch Press☆13Updated 7 years ago
- Yara syntax highlighting☆25Updated 3 years ago
- Extracts indicators of compromise (IOCs), including domain names, IPv4 addresses, email addresses, and hashes, from text.☆13Updated 7 years ago
- misc scripts☆36Updated 6 years ago
- Multiple rules for yara-project for detect compiler/packer/protector☆33Updated 5 years ago
- Library and tools to access the Windows SuperFetch database format☆12Updated 9 months ago
- Digital Forensics Windows Registry (dfWinReg)☆51Updated 3 months ago
- ☆15Updated 7 years ago
- Chrome extension to extract data from websites surfed inside of chrome☆18Updated 10 years ago
- Carves EXEs from given data files, using intelligent carving based upon PE headers☆38Updated 7 years ago
- Artefacts from various retefe campaigns☆10Updated 6 years ago
- A curated list of tools for incident response☆29Updated last year
- Carve Windows Prefetch files from arbitrary binary data☆14Updated 7 years ago
- MalRecon - Basic Malware Reconnaissance and Analysis Tool☆26Updated 7 years ago
- "Fuzzy matching" for SQLite databases☆29Updated 4 years ago
- Library and tools to access the Microsoft Internet Explorer (MSIE) Cache File (index.dat) files☆16Updated 8 months ago
- Decode security descriptors in $Secure on NTFS☆20Updated 3 years ago
- Rekall Forensics and Incident Response Framework with rVMI extensions☆33Updated 4 years ago
- Convert Windows Netmon Monitor Mode Wireless Packet Captures to Libpcap Format☆15Updated 5 years ago
- radare2 script to help on COM objects reverse engineering☆11Updated 7 years ago
- CIRCL system forensic tools or a jumble of tools to support forensic☆42Updated 2 years ago
- Tools to work with vulnerability standards.☆19Updated 11 years ago
- Fast Evidence Collector Toolkit is an incident response toolkit to collect evidences on a suspicious windows computer☆42Updated 4 years ago
- smtp-user-enum.pl ported into a recon-ng module.☆9Updated 10 years ago
- Tool for analysis of Windows Prefetch files☆26Updated 6 years ago
- pure Python binary analysis framework☆23Updated 6 years ago