thewhiteninja / ntfstoolLinks
Forensics tool for NTFS (parser, mft, bitlocker, deleted files)
☆541Updated 2 years ago
Alternatives and similar repositories for ntfstool
Users that are interested in ntfstool are comparing it to the libraries listed below
Sorting:
- The multi-platform memory acquisition tool.☆860Updated last week
- PE-bear (builds only)☆778Updated 2 years ago
- Dynamic unpacker based on PE-sieve☆774Updated last month
- Lnk Explorer Command line edition!!☆328Updated 9 months ago
- View ETW Provider manifest☆537Updated 11 months ago
- A wireshark plugin to instrument ETW☆573Updated 3 years ago
- Parses $MFT from NTFS file systems☆268Updated 5 months ago
- $MFT directory tree reconstruction & FILE record info☆314Updated last year
- Prefetch Explorer Command Line☆272Updated 9 months ago
- Linker/Compiler/Tool detector for Windows, Linux and MacOS.☆572Updated last week
- Moneta is a live usermode memory analysis tool for Windows with the capability to detect malware IOCs☆777Updated last year
- MemProcFS-Analyzer - Automated Forensic Analysis of Windows Memory Dumps for DFIR☆678Updated 3 months ago
- A PowerShell script that attempts to help malware analysts hide their VMware Windows VM's from malware that may be trying to evade analys…☆401Updated 9 months ago
- A Pin Tool for tracing API calls etc☆1,549Updated 3 weeks ago
- Living Off The Land Drivers☆1,303Updated this week
- Event Tracing For Windows (ETW) Resources☆404Updated 3 weeks ago
- Library and tools to access the Windows New Technology File System (NTFS)☆218Updated last week
- A PowerShell script that attempts to help malware analysts hide their Windows VirtualBox Windows VM's from malware that may be trying to …☆314Updated 3 months ago
- Windows registry file format specification☆348Updated 6 years ago
- Windows kernel and user mode emulation.☆1,770Updated 6 months ago
- An index of Windows binaries, including download links for executables such as exe, dll and sys files☆702Updated last week
- A tool that shows detailed information about named pipes in Windows☆693Updated 11 months ago
- An NTFS/FAT parser for digital forensics & incident response☆212Updated 3 weeks ago
- Windows Registry Knowledge Base☆186Updated last week
- strings2: An improved strings extraction tool.☆346Updated 3 years ago
- Process Monitor X v2☆636Updated last year
- Windows System Explorer☆867Updated last year
- Windows Filtering Platform Explorer☆297Updated last month
- Regshot is a small, free and open-source registry compare utility that allows you to quickly take a snapshot of your registry and then co…☆421Updated 6 years ago
- A Binary Genetic Traits Lexer Framework☆515Updated 2 months ago