thewhiteninja / ntfstoolLinks
Forensics tool for NTFS (parser, mft, bitlocker, deleted files)
☆576Updated 2 years ago
Alternatives and similar repositories for ntfstool
Users that are interested in ntfstool are comparing it to the libraries listed below
Sorting:
- The multi-platform memory acquisition tool.☆911Updated 2 months ago
- Dynamic unpacker based on PE-sieve☆789Updated 3 months ago
- View ETW Provider manifest☆557Updated last year
- $MFT directory tree reconstruction & FILE record info☆321Updated last year
- Parses $MFT from NTFS file systems☆282Updated 7 months ago
- PE-bear (builds only)☆780Updated 2 years ago
- MemProcFS-Analyzer - Automated Forensic Analysis of Windows Memory Dumps for DFIR☆689Updated 2 months ago
- Lnk Explorer Command line edition!!☆331Updated 11 months ago
- Event Tracing For Windows (ETW) Resources☆412Updated last month
- A wireshark plugin to instrument ETW☆577Updated 3 years ago
- Library and tools to access the Windows New Technology File System (NTFS)☆222Updated last week
- Prefetch Explorer Command Line☆276Updated 11 months ago
- Windows registry file format specification☆352Updated 7 years ago
- Living Off The Land Drivers☆1,352Updated last week
- A PowerShell script that attempts to help malware analysts hide their Windows VirtualBox Windows VM's from malware that may be trying to …☆392Updated 5 months ago
- Linker/Compiler/Tool detector for Windows, Linux and MacOS.☆571Updated this week
- RegRipper3.0☆668Updated last year
- Moneta is a live usermode memory analysis tool for Windows with the capability to detect malware IOCs☆792Updated last year
- A Pin Tool for tracing API calls etc☆1,592Updated last month
- An NTFS/FAT parser for digital forensics & incident response☆218Updated last month
- A PowerShell script that attempts to help malware analysts hide their VMware Windows VM's from malware that may be trying to evade analys…☆421Updated 11 months ago
- Memory acquisition for Linux that makes sense.☆215Updated 2 years ago
- Encyclopedia for Executables☆465Updated 4 years ago
- A tool that shows detailed information about named pipes in Windows☆718Updated last year
- Process Monitor X v2☆642Updated last year
- Windows Registry Knowledge Base☆191Updated this week
- Arsenal Image Mounter mounts the contents of disk images as complete disks in Microsoft Windows.☆681Updated last week
- PE file viewer/editor for Windows, Linux and MacOS.☆1,171Updated this week
- Windows System Explorer☆870Updated 3 weeks ago
- An index of Windows binaries, including download links for executables such as exe, dll and sys files☆738Updated this week