awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
Back to thewhiteninja/ntfstool

Projects sharing features with Ntfstool

30 open-source projects similar to thewhiteninja/ntfstool, ranked by shared indexed features. Tags may describe platforms or build tools rather than the same primary purpose. Check each project’s use case, license, and deployment requirements before treating it as a replacement.

  • yamato-security/hayabusaYamato-Security avatar

    Yamato-Security/hayabusa

    3,027View on GitHub↗

    Hayabusa is a Windows event log analyzer, threat hunting tool, and forensic timeline generator. It functions as a detection engine that applies threat patterns to logs to identify suspicious behavior and security threats. The project distinguishes itself through the ability to synchronize detection rules from remote repositories and tune risk levels to prioritize critical alerts. It also provides specialized forensic capabilities, such as extracting event log data into chronological records for incident response investigations. The tool's broader capabilities include security log enrichment

    Rustattackcybersecuritydetection
    View on GitHub↗3,027
  • jpcertcc/logontracerJPCERTCC avatar

    JPCERTCC/LogonTracer

    3,136View on GitHub↗

    LogonTracer is a security auditing tool designed for logon analysis and forensic log auditing. It functions as a dockerized security auditor that utilizes a security event graph database to map account names and network addresses, allowing for the visualization of complex system compromise patterns and authentication paths. The system features a Sigma detection engine that scans imported event logs against standardized rule sets to identify known malicious activity. It also includes an anomalous behavior detector that applies statistical analysis, graph algorithms, and hidden Markov models to

    Pythonactive-directoryblueteamdfir
    View on GitHub↗3,136
  • lazza/recuperabitLazza avatar

    Lazza/RecuperaBit

    610View on GitHub↗
    Pythondfirdiskforensics
    View on GitHub↗610
  • williballenthin/python-ntfswilliballenthin avatar

    williballenthin/python-ntfs

    86View on GitHub↗

    Open source Python library for NTFS analysis

    Python
    View on GitHub↗86

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Find more with AI search
  • bsi-bund/rdpcachestitcherBSI-Bund avatar

    BSI-Bund/RdpCacheStitcher

    329View on GitHub↗

    RdpCacheStitcher is a tool that supports forensic analysts in reconstructing useful images out of RDP cache bitmaps. Using raw RDP cache tile bitmaps extracted by tools like e.g. ANSSI's BMC-Tools (https://github.com/ANSSI-FR/bmc-tools) as input, it provides a graphical user interface and…

    C++
    View on GitHub↗329
  • cgosec/blauhauntcgosec avatar

    cgosec/Blauhaunt

    184View on GitHub↗

    A tool collection for filtering and visualizing logon events. Designed to help answering the "Cotton Eye Joe" question (Where did you come from where did you go) in Security Incidents and Threat Hunts

    JavaScript
    View on GitHub↗184
  • forensicartifacts/artifactsForensicArtifacts avatar

    ForensicArtifacts/artifacts

    1,240View on GitHub↗

    Digital Forensics artifact repository

    Python
    View on GitHub↗1,240
  • poorbillionaire/usn-journal-parserPoorBillionaire avatar

    PoorBillionaire/USN-Journal-Parser

    118View on GitHub↗

    Python script to parse the NTFS USN Journal

    Python
    View on GitHub↗118
  • yampelo/beagleyampelo avatar

    yampelo/beagle

    1,347View on GitHub↗

    Beagle is an incident response and digital forensics tool which transforms security logs and data into graphs.

    Python
    View on GitHub↗1,347
  • velocidex/velociraptorVelocidex avatar

    Velocidex/velociraptor

    3,769View on GitHub↗

    Velociraptor is a digital forensics and incident response platform, endpoint detection and response system, and visibility tool. It provides a query engine and remote forensic collector used to hunt for indicators of compromise and perform triage across a fleet of hosts. The system is distinguished by its specialized query language for interrogating host state and parsing binary files. It features a notebook environment that combines markdown documentation with executable query cells to standardize investigative workflows and enable collaborative reporting. The platform covers a wide range o

    Godigital-forensicsendpoint-discoveryendpoint-protection
    View on GitHub↗3,769
  • abdulrhmanalfaifi/fennecA

    AbdulRhmanAlfaifi/Fennec

    0View on GitHub↗
    View on GitHub↗0
  • airbus-cert/regrippyairbus-cert avatar

    airbus-cert/regrippy

    215View on GitHub↗

    A modern Python-3-based alternative to RegRipper

    Python
    View on GitHub↗215
  • airbus-cert/winsharkairbus-cert avatar

    airbus-cert/Winshark

    580View on GitHub↗
    Luaetwpcapwireshark
    View on GitHub↗580
  • aisk/rust-memcacheaisk avatar

    aisk/rust-memcache

    148View on GitHub↗

    memcache client for rust

    Rustcacheclientdriver
    View on GitHub↗148
  • ahmedkhlief/apt-hunterahmedkhlief avatar

    ahmedkhlief/APT-Hunter

    1,408View on GitHub↗

    APT-Hunter is Threat Hunting tool for windows event logs which made by purple team mindset to provide detect APT movements hidden in the sea of windows event logs to decrease the time to uncover suspicious activity

    Python
    View on GitHub↗1,408
  • aarsakian/mftextractoraarsakian avatar

    aarsakian/MFTExtractor

    18View on GitHub↗

    FileSystemForensics

    Go
    View on GitHub↗18
  • 3coresec/automata3

    3CORESec/Automata

    0View on GitHub↗
    View on GitHub↗0
  • activecm/beakerA

    activecm/BeaKer

    0View on GitHub↗
    View on GitHub↗0
  • anssi-fr/bmc-toolsA

    ANSSI-FR/bmc-tools

    0View on GitHub↗
    View on GitHub↗0
  • andreafortuna/autotimelinerA

    andreafortuna/autotimeliner

    0View on GitHub↗
    View on GitHub↗0
  • anssi-fr/dfir-o365rcA

    ANSSI-FR/DFIR-O365RC

    0View on GitHub↗
    View on GitHub↗0
  • anssi-fr/dfir4vsphereA

    ANSSI-FR/DFIR4vSphere

    0View on GitHub↗
    View on GitHub↗0
  • apecloud/ape-dtsapecloud avatar

    apecloud/ape-dts

    580View on GitHub↗

    ApeCloud's Data Transfer Suite, written in Rust. Provides ultra-fast data replication between MySQL, PostgreSQL, Redis, MongoDB, Kafka and ClickHouse, ideal for disaster recovery (DR) and migration scenarios.

    Rustbinlogcdcclickhouse
    View on GitHub↗580
  • aquasecurity/traceeaquasecurity avatar

    aquasecurity/tracee

    4,377View on GitHub↗

    Tracee is a cloud-native runtime security and forensics tool that uses eBPF to capture system calls and kernel events in real time. It operates as a standalone binary or a Helm-deployable agent for Kubernetes, normalizing system calls, network events, and container activities into a unified event pipeline for consistent analysis. The tool distinguishes itself through policy-driven event filtering using YAML-based rules, allowing users to target specific workloads and reduce noise during monitoring. It includes built-in threat detection signatures that flag suspicious behavioral patterns witho

    Gobpfdockerebpf
    View on GitHub↗4,377
  • artemeff/eqlartemeff avatar

    artemeff/eql

    117View on GitHub↗

    Erlang with SQL, inspired by yesql.

    Erlang
    View on GitHub↗117
  • artemeff/qspartemeff avatar

    artemeff/qsp

    18View on GitHub↗

    QSP is enhanced Erlang query string parser, that supports nested arrays, hashes and returns maps. Requires Erlang 17.0 and better. Extracted from Plug.

    Erlang
    View on GitHub↗18
  • asimihsan/cwl-mountA

    asimihsan/cwl-mount

    0View on GitHub↗
    View on GitHub↗0
  • avilladaniel/avillaforensicsA

    AvillaDaniel/AvillaForensics

    0View on GitHub↗

    Avilla Forensics is a free mobile forensic tool created in February 2021 to assist investigators in collecting information and evidence from mobile devices. Developed by Daniel Avilla, a police officer from São Paulo, the tool provides powerful features for logical data extraction and backup…

    View on GitHub↗0
  • awesome-spark/awesome-sparkawesome-spark avatar

    awesome-spark/awesome-spark

    1,882View on GitHub↗

    A curated list of awesome Apache Spark packages and resources.

    Shellapache-sparkawesomepyspark
    View on GitHub↗1,882
  • accenture/docker-plasoA

    Accenture/docker-plaso

    0View on GitHub↗
    View on GitHub↗0