Willi Ballenthin

Results 23 repositories owned by Willi Ballenthin

LfLe

25
Stars
13
Forks
Watchers

Recover event log entries from an image by heurisitically looking for record structures.

process-forest

143
Stars
29
Forks
Watchers

Reconstruct process trees from event logs

python-dotnet-binaryformat

45
Stars
6
Forks
Watchers

Pure Python parser for data encoded by .NET's BinaryFormatter

python-evt

40
Stars
12
Forks
Watchers

Pure Python parser for classic Windows Event Log files (.evt)

python-idb

445
Stars
111
Forks
Watchers

Pure Python parser and analyzer for IDA Pro database files (.idb).

python-ntfs

76
Stars
26
Forks
Watchers

Open source Python library for NTFS analysis

python-registry

416
Stars
102
Forks
Watchers

Pure Python parser for Windows Registry hives.

python-sdb

102
Stars
27
Forks
Watchers

Pure Python parser for Application Compatibility Shim Databases (.sdb files)

python-vb

38
Stars
9
Forks
Watchers

analysis of visual basic code

shellbags

147
Stars
38
Forks
Watchers

Cross-platform, open-source shellbag parser