liblnk Logo

liblnk

0
Free
Visit Website

liblnk is a library to access the Windows Shortcut File (LNK) format. It provides a way to read and parse LNK files, with planned features including data block support, shell item support, and multi-threading support. The library is currently in alpha status and is licensed under LGPLv3+.

FEATURES

ALTERNATIVES

Easy-to-use live forensics toolbox for Linux endpoints with various capabilities such as process inspection, memory analysis, and YARA scanning.

Open source tool for generating YARA rules about installed software from a running OS.

A Windows Registry hive extraction library that reads and writes Windows Registry 'hive' binary files.

Recover event log entries from an image by heuristically looking for record structures.

Hoarder is a tool to collect and parse windows artifacts.

A library to access and read QEMU Copy-On-Write (QCOW) image file formats with support for zlib compression and AES-CBC encryption.

A utility for recovering deleted files from ext3 or ext4 partitions.

A tool for parsing and extracting information from the Master File Table of NTFS file systems.

PINNED