thewhiteninja / ntfstoolLinks
Forensics tool for NTFS (parser, mft, bitlocker, deleted files)
☆536Updated 2 years ago
Alternatives and similar repositories for ntfstool
Users that are interested in ntfstool are comparing it to the libraries listed below
Sorting:
- The multi-platform memory acquisition tool.☆827Updated 2 months ago
- PE-bear (builds only)☆781Updated 2 years ago
- Dynamic unpacker based on PE-sieve☆753Updated 3 months ago
- View ETW Provider manifest☆530Updated 10 months ago
- Event Tracing For Windows (ETW) Resources☆398Updated 10 months ago
- Lnk Explorer Command line edition!!☆320Updated 7 months ago
- $MFT directory tree reconstruction & FILE record info☆311Updated 10 months ago
- Parses $MFT from NTFS file systems☆259Updated 3 months ago
- MemProcFS-Analyzer - Automated Forensic Analysis of Windows Memory Dumps for DFIR☆671Updated last month
- Living Off The Land Drivers☆1,271Updated this week
- A PowerShell script that attempts to help malware analysts hide their Windows VirtualBox Windows VM's from malware that may be trying to …☆306Updated last month
- Moneta is a live usermode memory analysis tool for Windows with the capability to detect malware IOCs☆770Updated last year
- A Pin Tool for tracing API calls etc☆1,528Updated 2 months ago
- Windows Registry Knowledge Base☆184Updated 10 months ago
- Prefetch Explorer Command Line☆263Updated 7 months ago
- A PowerShell script that attempts to help malware analysts hide their VMware Windows VM's from malware that may be trying to evade analys…☆382Updated 7 months ago
- A wireshark plugin to instrument ETW☆565Updated 3 years ago
- Library and tools to access the Windows New Technology File System (NTFS)☆215Updated last year
- Linker/Compiler/Tool detector for Windows, Linux and MacOS.☆567Updated this week
- Memory acquisition for Linux that makes sense.☆205Updated last year
- Windows System Explorer☆865Updated last year
- Arsenal Image Mounter mounts the contents of disk images as complete disks in Microsoft Windows.☆633Updated last week
- Process Monitor X v2☆630Updated last year
- Windows registry file format specification☆343Updated 6 years ago
- A tool that shows detailed information about named pipes in Windows☆690Updated 9 months ago
- PE file viewer/editor for Windows, Linux and MacOS.☆1,131Updated this week
- Regshot is a small, free and open-source registry compare utility that allows you to quickly take a snapshot of your registry and then co…☆400Updated 6 years ago
- PoCs and tools for investigation of Windows process execution techniques☆935Updated last month
- Encyclopedia for Executables☆449Updated 3 years ago
- ☆503Updated last year