
LogFileParser
Parser for $LogFile on NTFS
binary-analysisdata-recoverydigital-forensics+3
220

Parser for $LogFile on NTFS

Live monitoring tool for remote PowerShell sessions using ETW to capture and decode WinRM/PSRP protocol, providing command execution traces and…

Collection of radare2 scripts for malware analysis: carve binaries from memory dumps, patch PE headers, and decode hashed function imports in…

Decodes PlugX traffic and encrypted/compressed artifacts