thewhiteninja / ntfstoolLinks
Forensics tool for NTFS (parser, mft, bitlocker, deleted files)
☆526Updated last year
Alternatives and similar repositories for ntfstool
Users that are interested in ntfstool are comparing it to the libraries listed below
Sorting:
- The multi-platform memory acquisition tool.☆808Updated last month
- Dynamic unpacker based on PE-sieve☆739Updated last month
- View ETW Provider manifest☆502Updated 8 months ago
- Parses $MFT from NTFS file systems☆252Updated 2 months ago
- PE-bear (builds only)☆780Updated 2 years ago
- A wireshark plugin to instrument ETW☆561Updated 3 years ago
- Event Tracing For Windows (ETW) Resources☆391Updated 9 months ago
- Lnk Explorer Command line edition!!☆312Updated 6 months ago
- MemProcFS-Analyzer - Automated Forensic Analysis of Windows Memory Dumps for DFIR☆649Updated 3 weeks ago
- $MFT directory tree reconstruction & FILE record info☆306Updated 9 months ago
- A Pin Tool for tracing API calls etc☆1,494Updated last month
- Library and tools to access the Windows New Technology File System (NTFS)☆210Updated last year
- Moneta is a live usermode memory analysis tool for Windows with the capability to detect malware IOCs☆762Updated last year
- Linker/Compiler/Tool detector for Windows, Linux and MacOS.☆559Updated this week
- A PowerShell script that attempts to help malware analysts hide their VMware Windows VM's from malware that may be trying to evade analys…☆371Updated 5 months ago
- Prefetch Explorer Command Line☆260Updated 6 months ago
- An index of Windows binaries, including download links for executables such as exe, dll and sys files☆677Updated this week
- Living Off The Land Drivers☆1,223Updated 2 weeks ago
- A PowerShell script that attempts to help malware analysts hide their Windows VirtualBox Windows VM's from malware that may be trying to …☆300Updated 2 weeks ago
- A tool that shows detailed information about named pipes in Windows☆684Updated 8 months ago
- Windows registry file format specification☆340Updated 6 years ago
- Process Monitor X v2☆616Updated last year
- Encyclopedia for Executables☆447Updated 3 years ago
- A Binary Genetic Traits Lexer Framework☆496Updated last week
- A GUI and CLI tool for removing bloat from executables☆408Updated 2 weeks ago
- Regshot is a small, free and open-source registry compare utility that allows you to quickly take a snapshot of your registry and then co…☆380Updated 6 years ago
- Important notes and topics on my journey towards mastering Windows Internals☆397Updated last year
- Assortment of hashing algorithms used in malware☆366Updated 2 weeks ago
- Windows Registry Knowledge Base☆176Updated 9 months ago
- Arsenal Image Mounter mounts the contents of disk images as complete disks in Microsoft Windows.☆618Updated last week