libyal / winreg-kb
Windows Registry Knowledge Base
☆173Updated 6 months ago
Alternatives and similar repositories for winreg-kb:
Users that are interested in winreg-kb are comparing it to the libraries listed below
- $MFT directory tree reconstruction & FILE record info☆304Updated 6 months ago
- AppCompatCache (shimcache) parser. Supports Windows 7 (x86 and x64), Windows 8.x, and Windows 10☆117Updated 3 months ago
- Command line access to the Registry☆141Updated 2 weeks ago
- Windows 10 (v1803+) ActivitiesCache.db parsers (SQLite, PowerShell, .EXE)☆188Updated 2 years ago
- ☆65Updated last month
- Parses amcache.hve files, but with a twist!☆131Updated 3 months ago
- ☆146Updated 10 months ago
- Parses $MFT from NTFS file systems☆234Updated this week
- Parser for $UsnJrnl on NTFS☆110Updated 2 years ago
- An NTFS/FAT parser for digital forensics & incident response☆202Updated 5 months ago
- Windows Prefetch parser. Supports all known versions from Windows XP to Windows 10.☆112Updated 3 months ago
- C# based evtx parser with lots of extras☆299Updated 2 weeks ago
- Tool suite for inspecting NTFS artifacts.☆220Updated last year
- MFT parser☆65Updated 2 months ago
- Event Tracing For Windows (ETW) Resources☆374Updated 6 months ago
- A repo that contains recursive directory listings (using PowerShell) of a vanilla (clean) install of every Windows OS version to compare …☆158Updated 4 months ago
- SysmonX - An Augmented Drop-In Replacement of Sysmon☆214Updated 5 years ago
- Carve file metadata from NTFS index ($I30) attributes☆63Updated last year
- Events from all manifest-based and mof-based ETW providers across Windows 10 versions☆294Updated 11 months ago
- A parser of Windows Defender's DetectionHistory forensic artifact, containing substantial info about quarantined files and executables.☆113Updated 3 years ago
- Yet another registry parser☆132Updated 3 years ago
- ☆68Updated last month
- Script for parsing Symantec Endpoint Protection logs, VBNs, and ccSubSDK database.☆64Updated 2 years ago
- A better strings utility!☆131Updated 2 months ago
- Win 10/11 related research☆184Updated last year
- Lnk Explorer Command line edition!!☆299Updated 3 months ago
- ☆302Updated 4 years ago
- ☆90Updated 2 years ago
- Documentation repository☆44Updated 7 months ago
- Sysmon EDR POC Build within Powershell to prove ability.☆224Updated 3 years ago