thewhiteninja / ntfstoolLinks
Forensics tool for NTFS (parser, mft, bitlocker, deleted files)
☆555Updated 2 years ago
Alternatives and similar repositories for ntfstool
Users that are interested in ntfstool are comparing it to the libraries listed below
Sorting:
- The multi-platform memory acquisition tool.☆894Updated last month
- Dynamic unpacker based on PE-sieve☆783Updated 2 months ago
- PE-bear (builds only)☆780Updated 2 years ago
- Parses $MFT from NTFS file systems☆281Updated 7 months ago
- View ETW Provider manifest☆550Updated last year
- Library and tools to access the Windows New Technology File System (NTFS)☆222Updated last month
- Lnk Explorer Command line edition!!☆331Updated 10 months ago
- Living Off The Land Drivers☆1,342Updated last month
- A Pin Tool for tracing API calls etc☆1,583Updated last week
- A wireshark plugin to instrument ETW☆575Updated 3 years ago
- Linker/Compiler/Tool detector for Windows, Linux and MacOS.☆572Updated this week
- MemProcFS-Analyzer - Automated Forensic Analysis of Windows Memory Dumps for DFIR☆689Updated last month
- $MFT directory tree reconstruction & FILE record info☆321Updated last year
- Windows registry file format specification☆351Updated 7 years ago
- Prefetch Explorer Command Line☆275Updated 10 months ago
- An index of Windows binaries, including download links for executables such as exe, dll and sys files☆730Updated this week
- A PowerShell script that attempts to help malware analysts hide their Windows VirtualBox Windows VM's from malware that may be trying to …☆389Updated 5 months ago
- Arsenal Image Mounter mounts the contents of disk images as complete disks in Microsoft Windows.☆676Updated this week
- Event Tracing For Windows (ETW) Resources☆409Updated last month
- PE file viewer/editor for Windows, Linux and MacOS.☆1,167Updated this week
- A PowerShell script that attempts to help malware analysts hide their VMware Windows VM's from malware that may be trying to evade analys…☆416Updated 10 months ago
- Moneta is a live usermode memory analysis tool for Windows with the capability to detect malware IOCs☆789Updated last year
- A tool that shows detailed information about named pipes in Windows☆709Updated last year
- PoCs and tools for investigation of Windows process execution techniques☆945Updated last month
- A Binary Genetic Traits Lexer Framework☆517Updated 3 months ago
- Windows System Explorer☆871Updated last week
- Windows Shortcut file (LNK) parser☆106Updated 2 weeks ago
- Windows Registry Knowledge Base☆189Updated last week
- SHAREM is a shellcode analysis framework, capable of emulating more than 20,000 WinAPIs and virutally all Windows syscalls. It also conta…☆471Updated 5 months ago
- Converts a EXE into DLL☆1,351Updated 2 months ago