omerbenamram / winstructs
Parsers for common structures across windows formats.
☆12Updated last year
Alternatives and similar repositories for winstructs:
Users that are interested in winstructs are comparing it to the libraries listed below
- lnk_parser is a full rust implementation to parse windows LNK files☆17Updated 2 months ago
- Wrapper for TSK (Sleuth Kit) Bindings☆11Updated 2 years ago
- Manage Your Large Team of Consultants☆11Updated last month
- Windows file metadata / forensic tool.☆18Updated 6 months ago
- A document tagging library☆29Updated this week
- USN to JSON☆22Updated 4 years ago
- ☆33Updated 3 years ago
- NTFS file system specimens☆13Updated last year
- A golang implementation of a prefetch parser.☆19Updated 6 months ago
- ☆10Updated last year
- A pure PowerShell/ .NET DFIR capability that dumps the Windows SRUM (System Resource Usage Monitor) database to CSVs for analysis.☆13Updated 3 years ago
- Go implementation of an Extensible Storage Engine parser☆29Updated last month
- This is a repo for fetching Applocker event log by parsing the win-event log☆30Updated 2 years ago
- Windows registry samples☆23Updated 6 years ago
- A Windows registry file parser written in Rust☆37Updated last year
- ☆20Updated 2 weeks ago
- ☆34Updated 2 years ago
- Scripts and tools created for appx analysis talk (Magnet summit 2019)☆15Updated last year
- Parser for Windows PowerShell script block logs☆13Updated 2 months ago
- Just Another broken Registry Parser (JARP)☆16Updated 10 months ago
- Hundred Days of Yara Challenge☆12Updated 2 years ago
- Windows Thingies... but in Rust☆23Updated 2 years ago
- Scanner for certain IoCs☆11Updated last month
- Splunk Technology-AddOn for Aurora Sigma-Based EDR Agent. It helps parse and configure the necessary inputs to neatly consume Aurora EDR …☆13Updated 2 years ago
- Publicly shareable windows event log message data☆27Updated 5 years ago
- Repository containing malware analysis filters for the Windows SysInternals' - Process Monitor tool☆15Updated 4 years ago
- ☆22Updated 5 months ago
- LNK to JSON☆14Updated 6 years ago
- Scripts to for ready-to-use Velociraptor instance deployment in Azure☆13Updated last year
- volatility-runner is a command line application designed to speed up memory forensics using the volatility framework, primarily for insta…☆11Updated 5 years ago