sunsetkookaburra / rust-libesedbLinks
Safe Rust API to libesedb
☆11Updated last month
Alternatives and similar repositories for rust-libesedb
Users that are interested in rust-libesedb are comparing it to the libraries listed below
Sorting:
- Wrapper for TSK (Sleuth Kit) Bindings☆12Updated 2 years ago
- lnk_parser is a full rust implementation to parse windows LNK files☆20Updated 3 months ago
- A document tagging library☆30Updated 7 months ago
- Manage Your Large Team of Consultants☆11Updated last month
- Keep it secret, keep it safe☆78Updated 9 months ago
- Extension blocks as found in ShellBags and other places in the Registry☆25Updated 10 months ago
- Indicators of Normality☆11Updated 3 years ago
- Windows Event Log Knowledge Base☆28Updated 3 weeks ago
- $MFT parser (from live systems or a copy of the $MFT) and raw file copy utility☆38Updated last year
- Lnk file parser☆90Updated 5 months ago
- A parser for the MFT (Master File Table) format☆149Updated last month
- Windows eventlog formatting, live fetching and querying utility in C☆20Updated 5 years ago
- ☆61Updated last year
- ☆20Updated 3 years ago
- Parsers for common structures across windows formats.☆12Updated 2 years ago
- A repo that contains a recursive dump from the ROOT key of every Windows Registry hive (using KAPE) from a vanilla (clean) install of eve…☆48Updated last week
- MFT parser☆72Updated 9 months ago
- An efficient tool for search files, directories, and alternate data streams directly from NTFS image files.☆27Updated last year
- Forensic framework to build tools that can be reused in multiple projects without changing anything☆29Updated 3 weeks ago
- WhiteBeam: Transparent endpoint security☆101Updated 2 years ago
- Live memory analysis detecting malware IOCs in processes, modules, handles, tokens, threads, .NET assemblies, memory address space and en…☆43Updated last year
- Splunk Technology-AddOn for Aurora Sigma-Based EDR Agent. It helps parse and configure the necessary inputs to neatly consume Aurora EDR …☆13Updated 3 years ago
- CLI tool to compute the TypeRefHash for .NET binaries.☆19Updated 3 years ago
- extract and parse WEVT_TEMPLATEs from PE files☆18Updated last year
- Command line utility for copying files on NTFS using low level disk access☆37Updated last year
- Carve file metadata from NTFS index ($I30) attributes☆71Updated last year
- Timestomper and Timestamp checker with nanosecond accuracy for NTFS volumes☆53Updated 4 years ago
- Command and Control that uses NTP as the transport protocol.☆21Updated 3 years ago
- ☆16Updated 2 years ago
- Browse Windows Prefetch versions: 17,23,26,30v1/2,31 & some of SuperFetch .7db/.db's☆62Updated 10 months ago