ydkhatri / blackboxprotobufView external linksLinks
Blackbox protobuf is a library for decoding and modifying arbitrary protobuf messages without the protobuf type definition.
☆43Feb 12, 2022Updated 4 years ago
Alternatives and similar repositories for blackboxprotobuf
Users that are interested in blackboxprotobuf are comparing it to the libraries listed below
Sorting:
- Tools for macOS Forensic Bootable media☆15May 20, 2020Updated 5 years ago
- Python bindings for LZFSE☆18Jul 9, 2020Updated 5 years ago
- Scripts to extract compound bplists in the iOS -> KnowledgeC.db -> structuredmetadata table.☆27May 12, 2019Updated 6 years ago
- ☆24Mar 12, 2025Updated 11 months ago
- Library and tools to access the GUID Partition Table (GPT) volume system format☆11Dec 20, 2025Updated last month
- Queries for parsed spotlight database in sqlite☆13Dec 29, 2020Updated 5 years ago
- Parsers for common structures across windows formats.☆12Aug 23, 2023Updated 2 years ago
- Slides and material from my conference presentations☆16Mar 30, 2024Updated last year
- ☆11Aug 3, 2018Updated 7 years ago
- Fetching data from system☆12Jun 18, 2017Updated 8 years ago
- Scripts and tools created for appx analysis talk (Magnet summit 2019)☆19Feb 26, 2024Updated last year
- Registry to JSON. This Project is for learning purposes and is not maintained.☆12Dec 28, 2021Updated 4 years ago
- NTFS file system specimens☆13Jul 3, 2023Updated 2 years ago
- CryptnetURLCacheParser is a tool to parse CryptAPI cache files☆20Aug 3, 2024Updated last year
- A rewrite of laginimaineb MSM8974_exploit as a stand alone kernel module.☆18Feb 17, 2016Updated 9 years ago
- Forensic cheatsheets for use with cheat☆15Dec 2, 2021Updated 4 years ago
- Set up a quick and dirty audit log on an SQLite db.☆16May 16, 2013Updated 12 years ago
- Parser for Sdba memory pool tags☆21Jul 16, 2021Updated 4 years ago
- Just Another broken Registry Parser (JARP)☆16May 23, 2024Updated last year
- Lua bindings for the Unicorn CPU emulation engine☆18Jan 31, 2026Updated 2 weeks ago
- ☆18Jan 19, 2022Updated 4 years ago
- Regexplore is a Volatility plugin designed to mimic the functionality of the Registry Explorer plugins in EZsuite☆18Mar 31, 2023Updated 2 years ago
- Python web app for previewing data in a Chrome Profile Folder☆23Jul 1, 2024Updated last year
- A Model Context Protocol (MCP) server that integrates Volatility 3 memory forensics framework with Claude☆28Jul 7, 2025Updated 7 months ago
- Google Filestream Forensic Tool☆22Mar 10, 2022Updated 3 years ago
- A repo for centralizing ongoing research on the new Windows 10/11 DFIR artifact, EventTranscript.db.☆43Jul 18, 2022Updated 3 years ago
- Module(s) related to reading SEGB (fka "Biome") data from iOS, mascOS, etc.☆28Sep 9, 2025Updated 5 months ago
- A Threat hunter's playbook to aid the development of techniques and hypothesis for hunting campaigns.☆14Jul 18, 2018Updated 7 years ago
- Frida+AndroidAsync Implement interface service registration.☆20Aug 17, 2020Updated 5 years ago
- Silly proof-of-concept for a PDF chatroom☆21May 3, 2023Updated 2 years ago
- A tool for fetching DFIR and other GitHub tools.☆25Aug 2, 2025Updated 6 months ago
- Manage Your Large Team of Consultants☆11Sep 18, 2025Updated 4 months ago
- USN to JSON☆22Apr 4, 2020Updated 5 years ago
- Extension blocks as found in ShellBags and other places in the Registry☆25Jan 7, 2025Updated last year
- A fast & simple bootable GKI kernel flasher for boot image v2 and v3 devices.☆22Apr 19, 2021Updated 4 years ago
- lnk_parser is a full rust implementation to parse windows LNK files☆22Jul 12, 2025Updated 7 months ago
- Zig binding of Z Standard☆27Mar 27, 2023Updated 2 years ago
- Plugins for parsing CSV files in Timeline Explorer. This project allows for anyone to add more supported files (i,e. they get a Line #/ta…☆29May 5, 2025Updated 9 months ago
- Modified python version of Rolf Rolles' https://github.com/RolfRolles/HexRaysDeob to unflatten Emotet'S Control Flow Flattening☆27May 5, 2022Updated 3 years ago