woanware / JumpLister
☆18Updated 11 years ago
Alternatives and similar repositories for JumpLister:
Users that are interested in JumpLister are comparing it to the libraries listed below
- misc scripts☆36Updated 6 years ago
- It's not just UsnJrnl (USN Journal Records/Change Journal Records) parser.☆23Updated 6 years ago
- Crack your macros like the math pros.☆33Updated 8 years ago
- Various DFIR Tools☆26Updated 6 years ago
- Carve Windows Prefetch files from arbitrary binary data☆14Updated 7 years ago
- Parses the WMI object database....looking for persistence☆31Updated 5 years ago
- A Windows REG file to enable all default PowerShell logging on a system with PowerShell v5 installed☆16Updated 8 years ago
- Windows link file (shortcuts) examiner☆68Updated 10 months ago
- Emulates the Sysinternals Autoruns tool, but for DFIR purposes e.g. multi user processing☆55Updated 5 years ago
- $MFT parser (from live systems or a copy of the $MFT) and raw file copy utility☆36Updated 9 months ago
- A Microsoft Windows service to provide telemetry on Windows executable memory page changes to facilitate threat detection☆31Updated 4 years ago
- Decode security descriptors in $Secure on NTFS☆20Updated 3 years ago
- Extract compressed memory pages from page-aligned data☆45Updated 6 years ago
- An updated C# port of X-Ways X-Tensions API.☆12Updated 7 years ago
- Tools and Binaries to use with KAPE☆12Updated 5 years ago
- NTFS parser, plus linking capabilites between MFT LogFile and UsnJrnl☆37Updated 8 years ago
- Server for receiving autorun data from the clients☆13Updated 7 years ago
- Volatility memory forensics plugin for extracting Windows DNS Cache☆29Updated 8 years ago
- Script to parse Process Monitor XML log file, and give you a summary report.☆22Updated 8 years ago
- Tool for analysis of Windows Prefetch files☆26Updated 6 years ago
- Event Log Analysis Tools☆29Updated 8 years ago
- Recover event log entries from an image by heurisitically looking for record structures.☆27Updated 9 years ago
- A GC link parser for both linkfiles and jumplists.☆18Updated 8 years ago
- Windows registry samples☆23Updated 6 years ago
- Parse Microsoft shim databases☆30Updated 3 months ago
- Binaries for the log2timeline projects and dependencies☆39Updated 7 months ago
- RegRipper wrapper for simplified bulk parsing or registry hives☆9Updated 6 years ago
- Carve $MFT records from a chunk of data (for instance a memory dump)☆16Updated 8 years ago
- Plugins to add funtionality to ProcDOT. http://www.procdot.com☆23Updated last year
- Automating forensic data extraction, reduction, and overall triage of cold disk and memory images.☆21Updated 6 years ago