sumeshi / ntfsdump
An efficient tool for extracting files, directories, and alternate data streams directly from NTFS image files.
☆19Updated 9 months ago
Related projects ⓘ
Alternatives and complementary repositories for ntfsdump
- Windows Event Log Knowledge Base☆18Updated last month
- Tools for macOS Forensic Bootable media☆15Updated 4 years ago
- An efficient tool for search files, directories, and alternate data streams directly from NTFS image files.☆22Updated 9 months ago
- extract and parse WEVT_TEMPLATEs from PE files☆18Updated 10 months ago
- Rekall Memory Forensic Framework☆29Updated 5 years ago
- Support Windows OS Reversing by searching easily for references to functions across many DLLs☆33Updated 2 years ago
- ☆26Updated 3 weeks ago
- An IDA plugin to deal with Event Tracing for Windows (ETW)☆50Updated 2 years ago
- ☆24Updated 5 years ago
- Invoke-DetectItEasy is a wrapper for excelent tool called Detect-It-Easy. This PS module is very useful for Threat Hunting and Forensics.☆23Updated 2 years ago
- Analysis tool for estimating the likelihood that a binary contains compressed or encrypted bytes☆42Updated 9 months ago
- Parse Microsoft shim databases☆29Updated 2 months ago
- Repository of vulnerabilities disclosed by ESET☆27Updated 2 years ago
- ☆17Updated 3 years ago
- ☆20Updated 2 months ago
- This is a simple tool to dump all the reparse points on an NTFS volume.☆31Updated 4 years ago
- A set of small utilities, helpers for PIN tracers☆31Updated last year
- A library for fast parse & import of Windows Master File Table($MFT) into Elasticsearch.☆11Updated 6 months ago
- An experimental dynamic malware unpacker based on Intel Pin and PE-sieve☆57Updated 3 months ago
- ☆18Updated 4 years ago
- A modular Karton Framework service that unpacks common packers like UPX and others using the Qiling Framework.☆51Updated 3 years ago
- Command line utility for copying files on NTFS using low level disk access☆32Updated 8 months ago
- Scans through registry hives outputting entropy values for key/values, dumps binary contents to files...we are looking for those "fileles…☆11Updated 5 years ago
- ☆55Updated last month
- Extract data of TTD trace file to a minidump☆28Updated last year
- Python 3 - Manipulation and conversation with different data type (Bytes operations)☆27Updated 2 years ago
- Registry hive parsing the async way☆19Updated 2 months ago
- Code samples that serve as references for Windows API functions☆12Updated 5 months ago
- ☆21Updated last month
- Collection of structures, prototype and examples for Microsoft Macro Assembler (MASM) x64.☆16Updated 4 years ago