msuhanov / winmem_decompressView external linksLinks
Extract compressed memory pages from page-aligned data
☆47Sep 25, 2018Updated 7 years ago
Alternatives and similar repositories for winmem_decompress
Users that are interested in winmem_decompress are comparing it to the libraries listed below
Sorting:
- Windows registry samples☆24Nov 18, 2018Updated 7 years ago
- Technical add-on to ingest json formatted volatility memory analysis plugin outputs☆13May 21, 2018Updated 7 years ago
- Registry to JSON. This Project is for learning purposes and is not maintained.☆12Dec 28, 2021Updated 4 years ago
- ☆13Aug 17, 2020Updated 5 years ago
- MacOS incident Response Toolkit. Mostly written while stuck on a NJTransit train.☆20Feb 20, 2020Updated 5 years ago
- NTFS Security Descriptor Stream ($Secure:$SDS) parser☆14Jan 9, 2023Updated 3 years ago
- An NTFS/FAT parser for digital forensics & incident response☆217Oct 31, 2025Updated 3 months ago
- An advanced parser for INDX records☆29Aug 7, 2019Updated 6 years ago
- It is based on bulk_extractor (https://github.com/simsong/bulk_extractor) and add scanners for record carving☆42Apr 23, 2020Updated 5 years ago
- Yet another registry parser☆138Apr 15, 2022Updated 3 years ago
- Carve NTFS USN records from binary data☆27May 21, 2017Updated 8 years ago
- Fast multipattern regular expression searching for digital forensics☆18Jul 31, 2019Updated 6 years ago
- Registry Miner☆14Apr 10, 2018Updated 7 years ago
- "Evolving AppCompat/AmCache data analysis beyond grep"☆209Sep 15, 2021Updated 4 years ago
- Maltego transforms to pivot between PE files based on their VirusTotal codeblocks☆19Jul 15, 2021Updated 4 years ago
- A Windows Event Processing Utility☆47Feb 21, 2018Updated 7 years ago
- NTFS samples☆27Aug 1, 2020Updated 5 years ago
- An updated C# port of X-Ways X-Tensions API.☆11Mar 12, 2018Updated 7 years ago
- Tool to decompress data from Windows 10 page files and memory dumps, that has been compressed by the Windows 10 memory manager.☆51Apr 9, 2019Updated 6 years ago
- Server for receiving autorun data from the clients☆13Sep 26, 2017Updated 8 years ago
- Library and tools to access the GUID Partition Table (GPT) volume system format☆11Dec 20, 2025Updated last month
- Wrapper for TSK (Sleuth Kit) Bindings☆12Jan 10, 2023Updated 3 years ago
- Demonstrate the behavior of the tunnel cache on Windows☆10Aug 13, 2019Updated 6 years ago
- Python unbup script for McAfee .bup files (with some additional fun features). This script is fully implemented in python it's not just a…☆37Apr 24, 2018Updated 7 years ago
- Small C++ library to produce GraphViz .gv files☆10Jan 23, 2023Updated 3 years ago
- GHARF is an efficient support framework for Red Team exercises that applies the concept of CI/CD☆35Jul 14, 2025Updated 7 months ago
- Duo MFA auditing tool to test users' likelihood of approving unexpected push notifications☆13Apr 20, 2018Updated 7 years ago
- Library and tools to access the Volume Shadow Snapshot (VSS) format☆114Dec 20, 2025Updated last month
- CPUID database derived from InstLatx64☆15Feb 1, 2020Updated 6 years ago
- Recovery tool to retrieve picture data from damaged jpeg files.☆11Nov 15, 2023Updated 2 years ago
- ☆11Mar 12, 2021Updated 4 years ago
- Various scrips☆12Oct 19, 2022Updated 3 years ago
- ☆11Aug 3, 2018Updated 7 years ago
- A library for fast parse & import of Windows Master File Table($MFT) into Elasticsearch.☆12Jun 23, 2025Updated 7 months ago
- A dedicated repo to interact with the API of Timesketch☆12Sep 17, 2021Updated 4 years ago
- Konrads' Pen-Ultimate (Windows) Log File Parser☆14Dec 27, 2025Updated last month
- My Year of Python Repository☆28Jun 13, 2020Updated 5 years ago
- Simple Windows Event Log Forwarder (SWELF). Its easy to use/simply works Log Forwarder and EVTX Parser. Almost in full release here at ht…☆24Jun 20, 2023Updated 2 years ago
- ReviveIT (revit) is a proof of concept file recovery tool (carver)☆12Dec 3, 2020Updated 5 years ago