thewhiteninja / ntfstoolLinks
Forensics tool for NTFS (parser, mft, bitlocker, deleted files)
☆584Updated 2 years ago
Alternatives and similar repositories for ntfstool
Users that are interested in ntfstool are comparing it to the libraries listed below
Sorting:
- The multi-platform memory acquisition tool.☆924Updated 3 months ago
- Dynamic unpacker based on PE-sieve☆793Updated 4 months ago
- Parses $MFT from NTFS file systems☆291Updated 8 months ago
- PE-bear (builds only)☆782Updated 2 years ago
- View ETW Provider manifest☆565Updated last year
- MemProcFS-Analyzer - Automated Forensic Analysis of Windows Memory Dumps for DFIR☆692Updated 2 months ago
- Event Tracing For Windows (ETW) Resources☆413Updated 2 months ago
- $MFT directory tree reconstruction & FILE record info☆323Updated last year
- Lnk Explorer Command line edition!!☆334Updated last year
- Prefetch Explorer Command Line☆277Updated last year
- A wireshark plugin to instrument ETW☆577Updated 3 years ago
- Library and tools to access the Windows New Technology File System (NTFS)☆223Updated last month
- Memory acquisition for Linux that makes sense.☆216Updated 2 years ago
- A PowerShell script that attempts to help malware analysts hide their Windows VirtualBox Windows VM's from malware that may be trying to …☆394Updated 6 months ago
- Living Off The Land Drivers☆1,363Updated last week
- Moneta is a live usermode memory analysis tool for Windows with the capability to detect malware IOCs☆798Updated last year
- A PowerShell script that attempts to help malware analysts hide their VMware Windows VM's from malware that may be trying to evade analys…☆424Updated 11 months ago
- Windows registry file format specification☆353Updated 7 years ago
- Windows Shortcut file (LNK) parser☆115Updated 2 months ago
- Windows Registry Knowledge Base☆193Updated 3 weeks ago
- A tool that shows detailed information about named pipes in Windows☆727Updated last year
- Linker/Compiler/Tool detector for Windows, Linux and MacOS.☆571Updated this week
- A Fast (and safe) parser for the Windows XML Event Log (EVTX) format☆869Updated 2 weeks ago
- Standard collection of rules for capa: the tool for enumerating the capabilities of programs☆664Updated last week
- A GUI and CLI tool for removing bloat from executables☆438Updated 6 months ago
- RegRipper3.0☆673Updated last year
- An index of Windows binaries, including download links for executables such as exe, dll and sys files☆745Updated this week
- PoCs and tools for investigation of Windows process execution techniques☆954Updated last week
- A Pin Tool for tracing API calls etc☆1,597Updated last month
- Handbook of windows forensic artifacts across multiple Windows version with interpretation tips and some examples. Work in progress!☆450Updated last year