Windows Forensic
Useful tool for Windows analysis
Forensic analysis on Windows platform can be done with many tools. Eric Zimmerman provide a wide range of them.
Each tool
Name | Version (.net 4 | 6) | Purpose |
---|---|---|
AmcacheParser | Amcache.hve parser with lots of extra features. Handles locked files | |
AppCompatCacheParser | AppCompatCache aka ShimCache parser. Handles locked files | |
bstrings | Find them strings yo. Built in regex patterns. Handles locked files | |
EvtxECmd | Event log (evtx) parser with standardized CSV, XML, and json output! Custom maps, locked file support, and more! | |
EZViewer | Standalone, zero dependency viewer for .doc, .docx, .xls, .xlsx, .txt, .log, .rtf, .otd, .htm, .html, .mht, .csv, and .pdf. Any non-supported files are shown in a hex editor (with data interpreter!) | |
Hasher | 2.0.0.0 | - | Hash all the things |
JLECmd | Jump List parser | |
JumpList Explorer | GUI based Jump List viewer | |
LECmd | Parse lnk files | |
MFTECmd | $MFT, $Boot, $J, $SDS, $I30, and $LogFile (coming soon) parser. Handles locked files | |
MFTExplorer | Graphical $MFT viewer | |
PECmd | Prefetch parser | |
RBCmd | Recycle Bin artifact (INFO2/$I) parser | |
RecentFileCacheParser | RecentFileCache parser | |
RECmd | Powerful command line Registry tool searching, multi-hive support, plugins, and more | |
Registry Explorer | Registry viewer with searching, multi-hive support, plugins, and more. Handles locked files | |
RLA | Replay transaction logs and update Registry hives so they are no longer dirty. Useful when tools do not know how to handle transaction logs | |
SDB Explorer | Shim database GUI | |
SBECmd | ShellBags Explorer, command line edition, for exporting shellbag data | |
ShellBags Explorer | GUI for browsing shellbags data. Handles locked files | |
SQLECmd | Find and process SQLite files according to your needs with maps! | |
SrumECmd | Process SRUDB.dat and (optionally) SOFTWARE hive for network, process, and energy info! | |
SumECmd | Process Microsoft User Access Logs found under 'C:\Windows\System32\LogFiles\SUM' | |
Timeline Explorer | View CSV and Excel files, filter, group, sort, etc. with ease | |
VSCMount | Mount all VSCs on a drive letter to a given mount point | |
WxTCmd | Windows 10 Timeline database parser |
Auto discover and update every tool
Last updated