liblnk Logo

liblnk

0
Free
Visit Website

liblnk is a library to access the Windows Shortcut File (LNK) format. It provides a way to read and parse LNK files, with planned features including data block support, shell item support, and multi-threading support. The library is currently in alpha status and is licensed under LGPLv3+.

FEATURES

ALTERNATIVES

A PowerShell-based incident response and live forensic data acquisition tool for Windows hosts.

Yara pattern matching tool for forensic investigations with predefined rules for magic headers in files and raw images.

A DFVFS backed viewer project with a WxPython GUI, aiming to enhance file extraction and viewing capabilities.

A comprehensive Linux log analysis tool that streamlines the investigation of security incidents by extracting and organizing critical details from supported log files.

Customizable live OS constructor tool for remote forensics and incident response.

View physical memory as files in a virtual file system for easy memory analysis and artifact access.

A Windows Registry hive extraction library that reads and writes Windows Registry 'hive' binary files.

DFIR ORC Documentation provides detailed instructions for setting up the build environment and deploying the tool.