t9t / gomft
NTFS Master File Table (MFT) parser for Go.
☆40Updated 3 months ago
Related projects ⓘ
Alternatives and complementary repositories for gomft
- An NTFS file parser in Go☆64Updated last week
- Go interface to NTDLL functions☆72Updated 7 months ago
- Golang parser for OLE files☆31Updated 5 months ago
- easy dll proxying in go☆13Updated 2 years ago
- Go library for ETW (Event Tracing for Windows) events processing☆60Updated 2 years ago
- A Portable Executable parser for Golang☆47Updated last year
- Command line utility for copying files on NTFS using low level disk access☆32Updated 8 months ago
- ☆36Updated 2 years ago
- enpoint detection / live analysis & sandbox host / signatures quality test☆42Updated 3 years ago
- ☆20Updated 5 years ago
- Go implementation of an Extensible Storage Engine parser☆27Updated 2 months ago
- Go wrapper for in-memory DLL module loader, MemoryModule☆32Updated 6 years ago
- Mainpulate, Steal and Modify Windows Tokens in Go☆70Updated last year
- Trace events in real time sessions☆43Updated last year
- Linux and Windows VMs evasion fully written in Go☆29Updated 3 weeks ago
- Process injection techniques written in Go.☆61Updated last year
- BPFDoor Source Code. Originally found from Chinese Threat Actor Red Menshen☆40Updated 2 years ago
- A client library to interact with Windows RPC services such as MS-SRVS and MS-RRP.☆44Updated last month
- Small visualizator for PE files☆67Updated last year
- EDR/AV Simulation for Malware Development☆12Updated last year
- Windows API/constants, identity, and WinHTTP/WinINet for Go.☆18Updated 4 months ago
- A library to make HTTP requests with the Windows winhttp API☆22Updated 9 months ago
- Golang package for parsing Windows shell link binary (lnk or Windows shortcut) files.☆36Updated 2 years ago
- Golang bindings for PE-sieve☆40Updated last year
- This repository has been moved to https://github.com/kirides/go-d3d☆53Updated last year
- Small tool to play with IOCs caused by Imageload events☆37Updated last year
- Loads a program into a memfd and runs it.☆12Updated 2 years ago
- Load and execute a common object file format (COFF) in the current process☆25Updated 8 months ago
- Pure Go rewrite of knockknock☆10Updated last year
- ☆33Updated 4 years ago