sunsetkookaburra / rust-libesedbLinks
Safe Rust API to libesedb
☆11Updated 5 months ago
Alternatives and similar repositories for rust-libesedb
Users that are interested in rust-libesedb are comparing it to the libraries listed below
Sorting:
- Wrapper for TSK (Sleuth Kit) Bindings☆12Updated 3 years ago
- lnk_parser is a full rust implementation to parse windows LNK files☆22Updated 6 months ago
- Keep it secret, keep it safe☆80Updated last year
- A document tagging library☆33Updated 10 months ago
- Manage Your Large Team of Consultants☆11Updated 4 months ago
- Forensic framework to build tools that can be reused in multiple projects without changing anything☆32Updated 3 months ago
- Extension blocks as found in ShellBags and other places in the Registry☆25Updated last year
- Parsers for common structures across windows formats.☆12Updated 2 years ago
- Windows Event Log Knowledge Base☆29Updated last month
- Live memory analysis detecting malware IOCs in processes, modules, handles, tokens, threads, .NET assemblies, memory address space and en…☆44Updated last year
- ☆21Updated 3 years ago
- An efficient tool for search files, directories, and alternate data streams directly from NTFS image files.☆28Updated last year
- MFT parser☆74Updated last year
- ☆16Updated 2 years ago
- ☆62Updated last year
- $MFT parser (from live systems or a copy of the $MFT) and raw file copy utility☆38Updated last year
- A parser for the MFT (Master File Table) format☆155Updated last month
- Indicators of Normality☆11Updated 3 years ago
- ☆39Updated 2 years ago
- This repository contains a variety of plugins and scripts, related to the Volatility framework.☆17Updated last year
- Browse Windows Prefetch versions: 17,23,26,30v1/2,31 & some of SuperFetch .7db/.db's☆64Updated last year
- API and CLI tool to fetch and query Chome DevTools heap snapshots (Python & Playwright)☆16Updated last year
- quASAR: ASAR manipulation made easy☆38Updated 3 years ago
- A repo that contains a recursive dump from the ROOT key of every Windows Registry hive (using KAPE) from a vanilla (clean) install of eve…☆54Updated 3 months ago
- Windows eventlog formatting, live fetching and querying utility in C☆20Updated 5 years ago
- Windows.EDB Browser☆60Updated 2 years ago
- Alternative YARA scanning engine☆73Updated 3 years ago
- Command line utility for copying files on NTFS using low level disk access☆40Updated last year
- Timestomper and Timestamp checker with nanosecond accuracy for NTFS volumes☆51Updated 4 years ago
- Automatic/Custom Destinations & LNK (MS-SHLLINK) Browser☆41Updated last year