williballenthin / python-registry
Pure Python parser for Windows Registry hives.
☆426Updated 11 months ago
Related projects ⓘ
Alternatives and complementary repositories for python-registry
- Regipy is an os independent python library for parsing offline registry hives☆244Updated 2 months ago
- ☆417Updated last year
- ☆273Updated last year
- Volatility plugins developed and maintained by the community☆342Updated 3 years ago
- analyzeMFT.py is designed to fully parse the MFT file from an NTFS filesystem and present the results as accurately as possible in multip…☆447Updated last month
- PowerShell script for deobfuscating encoded PowerShell scripts☆417Updated 3 years ago
- ☆294Updated 4 years ago
- YARA malware query accelerator (web frontend)☆414Updated this week
- A YARA-integrated process denial framework for Windows☆396Updated 4 years ago
- Automated Virtual Machine Generation and Cloaking for Cuckoo Sandbox.☆484Updated 6 months ago
- Tool suite for inspecting NTFS artifacts.☆215Updated last year
- Web App for Volatility framework☆380Updated this week
- ETW Python Library☆268Updated last year
- VolatilityBot – An automated memory analyzer for malware samples and memory dumps☆263Updated 3 years ago
- Python bindings for The Sleuth Kit (libtsk)☆93Updated last month
- A VBA parser and emulation engine to analyze malicious macros.☆1,055Updated 4 months ago
- Volatility plugin for extracts configuration data of known malware☆485Updated 11 months ago
- Yara integrated software to handle archive file data.☆299Updated 2 years ago
- Allows you to quickly query a Windows machine for RAM artifacts☆218Updated 4 years ago
- An open source script to perform malware static analysis on Portable Executable☆309Updated last year
- ☆506Updated 3 years ago
- Malware Configuration And Payload Extraction☆747Updated this week
- EVTXtract recovers and reconstructs fragments of EVTX log files from raw binary data, including unallocated space and memory images.☆190Updated 4 years ago
- PowerShell Obfuscation Detection Framework☆724Updated 11 months ago
- Artifact analysis tools by JPCERT/CC Analysis Center☆456Updated 4 months ago
- Commandline low level file extractor for NTFS☆274Updated 5 years ago
- YARA Rules I come across on the internet☆334Updated 7 months ago
- Web interface for the Volatility Memory Forensics Framework☆259Updated 7 years ago
- Imaginary C2 is a python tool which aims to help in the behavioral (network) analysis of malware. Imaginary C2 hosts a HTTP server which …☆443Updated 2 years ago