Windows Forensic

Useful tool for Windows analysis

Forensic analysis on Windows platform can be done with many tools. Eric Zimmerman provide a wide range of them.

Each tool

NameVersion (.net 4 | 6)Purpose

AmcacheParser

Amcache.hve parser with lots of extra features. Handles locked files

AppCompatCacheParser

AppCompatCache aka ShimCache parser. Handles locked files

bstrings

Find them strings yo. Built in regex patterns. Handles locked files

EvtxECmd

Event log (evtx) parser with standardized CSV, XML, and json output! Custom maps, locked file support, and more!

EZViewer

Standalone, zero dependency viewer for .doc, .docx, .xls, .xlsx, .txt, .log, .rtf, .otd, .htm, .html, .mht, .csv, and .pdf. Any non-supported files are shown in a hex editor (with data interpreter!)

Hasher

Hash all the things

JLECmd

Jump List parser

JumpList Explorer

GUI based Jump List viewer

LECmd

Parse lnk files

MFTECmd

$MFT, $Boot, $J, $SDS, $I30, and $LogFile (coming soon) parser. Handles locked files

MFTExplorer

Graphical $MFT viewer

PECmd

Prefetch parser

RBCmd

Recycle Bin artifact (INFO2/$I) parser

RecentFileCacheParser

RecentFileCache parser

RECmd

Powerful command line Registry tool searching, multi-hive support, plugins, and more

Registry Explorer

Registry viewer with searching, multi-hive support, plugins, and more. Handles locked files

RLA

Replay transaction logs and update Registry hives so they are no longer dirty. Useful when tools do not know how to handle transaction logs

SDB Explorer

Shim database GUI

SBECmd

ShellBags Explorer, command line edition, for exporting shellbag data

ShellBags Explorer

GUI for browsing shellbags data. Handles locked files

SQLECmd

Find and process SQLite files according to your needs with maps!

SrumECmd

Process SRUDB.dat and (optionally) SOFTWARE hive for network, process, and energy info!

SumECmd

Process Microsoft User Access Logs found under 'C:\Windows\System32\LogFiles\SUM'

Timeline Explorer

View CSV and Excel files, filter, group, sort, etc. with ease

VSCMount

Mount all VSCs on a drive letter to a given mount point

WxTCmd

Windows 10 Timeline database parser

Auto discover and update every tool

Last updated