libfwnt Logo

libfwnt

0
Free
Visit Website

libfwnt is a library for Windows NT data types, providing a set of functions to work with Windows NT data structures. It is licensed under LGPLv3+ and is currently in alpha status. The library provides a way to access and manipulate Windows NT data types, making it a useful tool for developers and researchers working with Windows systems. The project provides detailed documentation and guides on how to build from source, making it easy to get started with the library.

FEATURES

ALTERNATIVES

Collects and organizes Linux OS data for detailed analysis and incident response.

Educational CTF-styled challenges for Memory Forensics.

A modified version of GNU dd with added features like hashing and fast disk wiping.

Toolkit for performing acquisitions on iOS devices with logical and filesystem acquisition support.

MFT and USN parser for direct extraction in filesystem timeline format with YARA rule support.

A reverse engineering framework with a focus on usability and code cleanliness

Universal hexadecimal editor for computer forensics, data recovery, and IT security.

usbdeath is an anti-forensic tool that manipulates udev rules for known USB devices and performs actions on unknown USB device insertion or specific USB device removal.

PINNED