log2timeline / dfwinregLinks
Digital Forensics Windows Registry (dfWinReg)
☆52Updated 5 months ago
Alternatives and similar repositories for dfwinreg
Users that are interested in dfwinreg are comparing it to the libraries listed below
Sorting:
- An NTFS journal parser☆82Updated 9 years ago
- Extract common Windows artifacts from source images and VSCs☆65Updated 4 years ago
- Yet another registry parser☆132Updated 3 years ago
- Python IOC Editor☆63Updated 10 years ago
- Extract compressed memory pages from page-aligned data☆45Updated 6 years ago
- Recurse through a registry, identifying values with large data -- a registry malware hunter☆44Updated 8 years ago
- Decode security descriptors in $Secure on NTFS☆20Updated 3 years ago
- Binaries for the log2timeline projects and dependencies☆39Updated 9 months ago
- Example programs used in the automating DFIR series☆63Updated 6 years ago
- Some dfir stuff☆31Updated 3 years ago
- Fast incident overview☆40Updated 8 years ago
- Emulates the Sysinternals Autoruns tool, but for DFIR purposes e.g. multi user processing☆55Updated 6 years ago
- A Windows Event Processing Utility☆46Updated 7 years ago
- AuditParser☆60Updated 11 years ago
- A Rekall interactive document for a Memory Analysis workshop/course.☆43Updated 8 years ago
- ☆82Updated 8 years ago
- Recover event log entries from an image by heurisitically looking for record structures.☆27Updated 9 years ago
- Auxiliary scripts for Incident Response with ELK☆11Updated 9 years ago
- Various DFIR Tools☆26Updated 6 years ago
- Tool to parse SRU database☆24Updated 7 years ago
- RegRipper wrapper for simplified bulk parsing or registry hives☆9Updated 6 years ago
- Different DFIR and CTI utilities☆37Updated 5 years ago
- openioc_scan Volatility Framework plugin☆43Updated 9 years ago
- a GUI Interface for DFIR Open Source Tools☆10Updated 10 years ago
- Checks with NSRL RDS servers looking for for hash matches☆114Updated 4 years ago
- My Year of Python Repository☆28Updated 5 years ago
- onigiri - remote malware triage script☆24Updated 9 years ago
- ircollect☆31Updated 11 years ago
- Windows registry samples☆23Updated 6 years ago
- Parses the WMI object database....looking for persistence☆32Updated 5 years ago