
UnderlayCopy
PowerShell toolkit that extracts locked Windows files (SAM, SYSTEM, NTDS, ...) using MFT parsing and raw disk reads
data-recoverydigital-forensicsdisk-forensics+3
256

PowerShell toolkit that extracts locked Windows files (SAM, SYSTEM, NTDS, ...) using MFT parsing and raw disk reads

Use to copy a file from an NTFS partitioned volume by reading the raw volume and parsing the NTFS structures.

Kvasir: Penetration Test Data Management

POC experiments with Volume Shadow copy Service (VSS)

From UART to Root: Breaking Into the Xiaomi C200 via U-Boot