libesedb Logo

libesedb

0
Free
Visit Website

libesedb is a library to access the Extensible Storage Engine (ESE) Database File (EDB) format, used in various applications like Windows Search, Windows Mail, Exchange, Active Directory, etc. The library is still experimental and has planned features like multi-threading support. It also provides documentation and resources for forensic analysis of the Windows Search database and ESE Database File Knowledge Base.

FEATURES

ALTERNATIVES

DMG2IMG is a tool for converting Apple compressed dmg archives to standard image disk files with support for zlib, bzip2, and LZFSE compression.

A console program for file recovery through data carving.

A comprehensive Linux log analysis tool that streamlines the investigation of security incidents by extracting and organizing critical details from supported log files.

Educational CTF-styled challenges for Memory Forensics.

libevt is a library to access and parse Windows Event Log (EVT) files.

DFIR ORC Documentation provides detailed instructions for setting up the build environment and deploying the tool.

GVfs is a userspace virtual filesystem implementation for GIO with various backends and features.

View physical memory as files in a virtual file system for easy memory analysis and artifact access.

PINNED