msuhanov / regf
Windows registry file format specification
☆337Updated 6 years ago
Alternatives and similar repositories for regf:
Users that are interested in regf are comparing it to the libraries listed below
- Yet another library library (and tools)☆207Updated 2 months ago
- Events from all manifest-based and mof-based ETW providers across Windows 10 versions☆286Updated 10 months ago
- Tool suite for inspecting NTFS artifacts.☆219Updated last year
- View ETW Provider manifest☆461Updated 4 months ago
- Windows Registry Knowledge Base☆172Updated 5 months ago
- ETW Python Library☆276Updated last year
- Incident Response & Digital Forensics Debugging Extension☆375Updated 6 years ago
- Windows Prefetch parser. Supports all known versions from Windows XP to Windows 10.☆111Updated 2 months ago
- Library and tools to access the Windows XML Event Log (EVTX) format☆196Updated 5 months ago
- Library and tools to access the Windows New Technology File System (NTFS)☆201Updated 8 months ago
- FileInsight-plugins: decoding toolbox of McAfee FileInsight hex editor for malware analysis☆159Updated 2 months ago
- Extract Windows Defender database from vdm files and unpack it☆436Updated 5 years ago
- ☆426Updated last year
- Library and tools to access the Windows NT Registry File (REGF) format☆115Updated 6 months ago
- An NTFS/FAT parser for digital forensics & incident response☆199Updated 4 months ago
- Full featured, offline Registry parser in C#☆226Updated 2 months ago
- Portable Executable parsing library (from PE-bear)☆653Updated 6 months ago
- Tool to view and create Microsoft shim database files (SDB).☆112Updated 7 years ago
- zer0m0n driver for cuckoo sandbox☆358Updated 9 years ago
- Pure Python parser for Application Compatibility Shim Databases (.sdb files)☆108Updated 4 years ago
- Expriments☆452Updated 5 months ago
- Parser for $UsnJrnl on NTFS☆109Updated 2 years ago
- Monitor activity of any driver☆334Updated 4 years ago
- ☆213Updated 6 years ago
- Source code for File Test - Interactive File System Test Tool☆278Updated last month
- Lnk Explorer Command line edition!!☆290Updated 2 months ago
- Regipy is an os independent python library for parsing offline registry hives☆253Updated 3 months ago
- Named pipe I/O ETW provider for Windows☆69Updated 4 years ago
- Quickly debug shellcode extracted during malware analysis☆590Updated last year
- Expand compressed files from WinSxS folder☆153Updated 8 months ago