
pefile
pefile is a Python module to read and work with PE (Portable Executable) files

pefile is a Python module to read and work with PE (Portable Executable) files

Parses Windows .evtx logs to identify remote connections and public IPs by analyzing EventIDs related to remote logins and sessions.

analyzeMFT.py is designed to fully parse the MFT file from an NTFS filesystem and present the results as accurately as possible in multiple formats.

Script to parse Aircrack-ng captures into a SQLite database and extract useful information like handshakes, MGT identities, interesting relations…

A python script that can detect and parse loki-bot (malware) related network traffic. This script can be helpful to DFIR analysts and security…

A radare2 script to parse the gopclntab to facilitate Reverse Engineering Go binaries.

NTLMRawUnhide.py is a Python3 script designed to parse network packet capture files and extract NTLMv2 hashes in a crackable format. The following…


Parse and analyze a Windows Amcache.hve registry hive, VirusTotal integration.

machofile is a module to parse Mach-O binary files

ETW and WPP tracing tool for security research. Subscribes to multiple providers, auto-parses events to JSON, and supports advanced filtering,…

Asclepius validates backup integrity by restoring files and actively testing their recoverability. Instead of trusting metadata, it attempts to parse…

This is a repo for fetching Applocker event log by parsing the win-event log

A python script which allows you to parse GeoLocation data from your Image files stored in a dataset.It also produces output in CSV file and also in…

A tool to parse Firefox and Chrome HSTS databases into forensic artifacts!