thewhiteninja / ntfstool
Forensics tool for NTFS (parser, mft, bitlocker, deleted files)
☆494Updated last year
Alternatives and similar repositories for ntfstool:
Users that are interested in ntfstool are comparing it to the libraries listed below
- The multi-platform memory acquisition tool.☆726Updated 2 months ago
- Dynamic unpacker based on PE-sieve☆694Updated 3 weeks ago
- MemProcFS-Analyzer - Automated Forensic Analysis of Windows Memory Dumps for DFIR☆569Updated 2 months ago
- PE-bear (builds only)☆772Updated last year
- Parses $MFT from NTFS file systems☆214Updated last week
- Moneta is a live usermode memory analysis tool for Windows with the capability to detect malware IOCs☆723Updated 10 months ago
- $MFT directory tree reconstruction & FILE record info☆296Updated 3 months ago
- View ETW Provider manifest☆450Updated 2 months ago
- A Pin Tool for tracing API calls etc☆1,370Updated this week
- Library and tools to access the Windows New Technology File System (NTFS)☆198Updated 6 months ago
- Lnk Explorer Command line edition!!☆287Updated 2 weeks ago
- A PowerShell script that attempts to help malware analysts hide their Windows VirtualBox Windows VM's from malware that may be trying to …☆286Updated last year
- An easy-to-use library for emulating memory dumps. Useful for malware analysis (config extraction, unpacking) and dynamic analysis in gen…☆774Updated 11 months ago
- Windows System Explorer☆840Updated 8 months ago
- Windows kernel and user mode emulation.☆1,562Updated 9 months ago
- Linker/Compiler/Tool detector for Windows, Linux and MacOS.☆539Updated this week
- A PowerShell script that attempts to help malware analysts hide their VMware Windows VM's from malware that may be trying to evade analys…☆295Updated this week
- Living Off The Land Drivers☆1,091Updated this week
- Windows Registry Knowledge Base☆170Updated 3 months ago
- Event Tracing For Windows (ETW) Resources☆363Updated 3 months ago
- Native API header files for the System Informer project.☆1,094Updated 4 months ago
- http://moaistory.blogspot.com/2018/10/winsearchdbanalyzer.html☆121Updated 6 months ago
- Process Monitor X v2☆595Updated last year
- Prefetch Explorer Command Line☆237Updated 2 weeks ago
- Memory acquisition for Linux that makes sense.☆171Updated last year
- An NTFS/FAT parser for digital forensics & incident response☆198Updated 2 months ago
- A wireshark plugin to instrument ETW☆547Updated 3 years ago
- Windows registry file format specification☆335Updated 6 years ago
- RpcView is a free tool to explore and decompile Microsoft RPC interfaces☆949Updated last year
- Arsenal Image Mounter mounts the contents of disk images as complete disks in Microsoft Windows.☆557Updated this week