thewhiteninja / ntfstoolLinks
Forensics tool for NTFS (parser, mft, bitlocker, deleted files)
☆550Updated 2 years ago
Alternatives and similar repositories for ntfstool
Users that are interested in ntfstool are comparing it to the libraries listed below
Sorting:
- The multi-platform memory acquisition tool.☆869Updated last month
- PE-bear (builds only)☆780Updated 2 years ago
- Parses $MFT from NTFS file systems☆275Updated 6 months ago
- Dynamic unpacker based on PE-sieve☆778Updated 2 months ago
- MemProcFS-Analyzer - Automated Forensic Analysis of Windows Memory Dumps for DFIR☆686Updated 3 weeks ago
- Lnk Explorer Command line edition!!☆329Updated 10 months ago
- $MFT directory tree reconstruction & FILE record info☆318Updated last year
- View ETW Provider manifest☆546Updated last year
- A wireshark plugin to instrument ETW☆575Updated 3 years ago
- A PowerShell script that attempts to help malware analysts hide their VMware Windows VM's from malware that may be trying to evade analys…☆411Updated 9 months ago
- Library and tools to access the Windows New Technology File System (NTFS)☆220Updated 2 weeks ago
- Event Tracing For Windows (ETW) Resources☆406Updated 2 weeks ago
- Moneta is a live usermode memory analysis tool for Windows with the capability to detect malware IOCs☆785Updated last year
- Prefetch Explorer Command Line☆274Updated 10 months ago
- A Pin Tool for tracing API calls etc☆1,557Updated this week
- A PowerShell script that attempts to help malware analysts hide their Windows VirtualBox Windows VM's from malware that may be trying to …☆382Updated 4 months ago
- Memory acquisition for Linux that makes sense.☆213Updated last year
- Windows Registry Knowledge Base☆187Updated last month
- Windows registry file format specification☆350Updated 7 years ago
- Living Off The Land Drivers☆1,318Updated 2 weeks ago
- Windows System Explorer☆870Updated last year
- A tool that shows detailed information about named pipes in Windows☆699Updated last year
- RegRipper3.0☆656Updated 11 months ago
- A GUI and CLI tool for removing bloat from executables☆432Updated 4 months ago
- Windows kernel and user mode emulation.☆1,783Updated 7 months ago
- An index of Windows binaries, including download links for executables such as exe, dll and sys files☆711Updated this week
- Process Monitor X v2☆637Updated last year
- Important notes and topics on my journey towards mastering Windows Internals☆414Updated last year
- Linker/Compiler/Tool detector for Windows, Linux and MacOS.☆571Updated this week
- A Binary Genetic Traits Lexer Framework☆516Updated 3 months ago