Skip to main content

Cool tools

NameWhat is this tool used for?Status
dionysosScanner for various IoCsCrates.io Crates.io (latest)
es4forensicsprovides structs and functions to insert timeline data into an elasticsearch indexCrates.io docs.rs Crates.io (latest)
evtx2bodyfileparses evtx files into a bodyfileCrates.io Crates.io (latest)
evtxtoolsCollection of command line tools to correlate windows event logs. This set of tools is aimed to be used at forensic investigations.Crates.io Crates.io (latest)
mactime2Replacement for mactime which fixes some of its shortcomingsCrates.io Crates.io (latest) Codecov
mft2bodyfileparses an $MFT file to bodyfileCrateCrates.io
ntdsextract2Extraction of forensic artifacts from ntds.dit filesCrates.io Crates.io (latest)
procbinsCompresses all process binaries into a zip fileCrates.io Crates.io
regviewOffline-Viewer for Windows Registry FilesCrates.io Crates.io (latest)
rexgenA tool to create words based on regular expressionsGitHub issues
evtxviewevtxview is a GUI viewer for Microsoft Windows evtx files (Windows event logs). I'm hacking this tiny tool because I need such a tool in most forensic investigations.final, but boring
libe2eeC++-based library that implements Proxy-ReEncryption (AFGH-Scheme) and provides exporting and importing of JSON datastructurePoC, abondened