thewhiteninja / ntfstool
Forensics tool for NTFS (parser, mft, bitlocker, deleted files)
☆500Updated last year
Alternatives and similar repositories for ntfstool:
Users that are interested in ntfstool are comparing it to the libraries listed below
- The multi-platform memory acquisition tool.☆752Updated 3 months ago
- $MFT directory tree reconstruction & FILE record info☆298Updated 4 months ago
- Dynamic unpacker based on PE-sieve☆706Updated 3 weeks ago
- Parses $MFT from NTFS file systems☆221Updated 2 weeks ago
- MemProcFS-Analyzer - Automated Forensic Analysis of Windows Memory Dumps for DFIR☆588Updated last week
- A Pin Tool for tracing API calls etc☆1,385Updated last month
- PE-bear (builds only)☆773Updated last year
- Lnk Explorer Command line edition!!☆290Updated last month
- Prefetch Explorer Command Line☆243Updated last month
- Moneta is a live usermode memory analysis tool for Windows with the capability to detect malware IOCs☆731Updated 11 months ago
- Library and tools to access the Windows New Technology File System (NTFS)☆200Updated 7 months ago
- View ETW Provider manifest☆457Updated 4 months ago
- An NTFS/FAT parser for digital forensics & incident response☆199Updated 3 months ago
- Windows kernel and user mode emulation.☆1,596Updated this week
- Living Off The Land Drivers☆1,112Updated this week
- Process Monitor X v2☆598Updated last year
- Useful scripts for WinDbg using the debugger data model☆402Updated 11 months ago
- An index of Windows binaries, including download links for executables such as exe, dll and sys files☆634Updated this week
- Event Tracing For Windows (ETW) Resources☆362Updated 5 months ago
- PEiD detects most common packers, cryptors and compilers for PE files.☆269Updated 7 years ago
- Linker/Compiler/Tool detector for Windows, Linux and MacOS.☆543Updated this week
- RegRipper3.0☆579Updated 2 months ago
- A DTrace on Windows Reimplementation☆339Updated last month
- The Windows Kernel Programming book samples☆618Updated last year
- A Binary Genetic Traits Lexer Framework☆487Updated last week
- Windows 10 System Programming book samples☆417Updated 8 months ago
- Some of my publicly available Malware analysis and Reverse engineering.☆794Updated 9 months ago
- A tool that shows detailed information about named pipes in Windows☆612Updated 3 months ago
- A wireshark plugin to instrument ETW☆549Updated 3 years ago
- Extract $MFT record info and log it to a csv file.☆264Updated 4 months ago