
Kvasir
Kvasir: Penetration Test Data Management
data-recoveryinformation-gatheringlog-analysis+3
4289 years ago

Kvasir: Penetration Test Data Management

PowerShell toolkit that extracts locked Windows files (SAM, SYSTEM, NTDS, ...) using MFT parsing and raw disk reads

Use to copy a file from an NTFS partitioned volume by reading the raw volume and parsing the NTFS structures.

From UART to Root: Breaking Into the Xiaomi C200 via U-Boot

POC experiments with Volume Shadow copy Service (VSS)