msuhanov / regf
Windows registry file format specification
☆325Updated 6 years ago
Related projects ⓘ
Alternatives and complementary repositories for regf
- Events from all manifest-based and mof-based ETW providers across Windows 10 versions☆269Updated 6 months ago
- Yet another library library (and tools)☆201Updated last month
- Windows Registry Knowledge Base☆162Updated last month
- Library and tools to access the Windows New Technology File System (NTFS)☆190Updated 4 months ago
- Incident Response & Digital Forensics Debugging Extension☆372Updated 5 years ago
- FileInsight-plugins: decoding toolbox of McAfee FileInsight hex editor for malware analysis☆156Updated 2 weeks ago
- ETW Python Library☆268Updated last year
- Library and tools to access the Windows XML Event Log (EVTX) format☆190Updated last month
- Tool suite for inspecting NTFS artifacts.☆215Updated last year
- Full featured, offline Registry parser in C#☆223Updated this week
- dump windows PE files using ruby☆311Updated 4 months ago
- View ETW Provider manifest☆433Updated 3 weeks ago
- An NTFS/FAT parser for digital forensics & incident response☆192Updated 2 weeks ago
- ☆417Updated last year
- Library and tools to access the Windows NT Registry File (REGF) format☆107Updated 3 months ago
- KrabsETW provides a modern C++ wrapper and a .NET wrapper around the low-level ETW trace consumption functions.☆610Updated last week
- Parser for $LogFile on NTFS☆190Updated 11 months ago
- Library and tools to access the Windows Prefetch File (SCCA) format.☆71Updated this week
- Windows Prefetch parser. Supports all known versions from Windows XP to Windows 10.☆106Updated 3 months ago
- A VBA p-code disassembler☆458Updated 3 years ago
- Parser for $UsnJrnl on NTFS☆108Updated last year
- Expand compressed files from WinSxS folder☆146Updated 4 months ago
- Portable Executable parsing library (from PE-bear)☆648Updated 2 months ago
- zer0m0n driver for cuckoo sandbox☆356Updated 9 years ago
- Document ETW providers☆207Updated 4 years ago
- Regipy is an os independent python library for parsing offline registry hives☆244Updated 2 months ago
- Print compiler information stored in Rich Header of PE executables.☆125Updated this week
- Source code for File Test - Interactive File System Test Tool☆260Updated last week
- RpcView is a free tool to explore and decompile Microsoft RPC interfaces☆927Updated last year
- Extract Windows Defender database from vdm files and unpack it☆425Updated 4 years ago