Pinned Repositories
EaTools
Analysis and manipulation of extended attribute ($EA) on NTFS
ExtractUsnJrnl
Tool to extract the $UsnJrnl from an NTFS volume
Indx2Csv
An advanced parser for INDX records
LogFileParser
Parser for $LogFile on NTFS
Mft2Csv
Extract $MFT record info and log it to a csv file.
PowerMft
Powerful commandline $MFT record editor.
RawCopy
Commandline low level file extractor for NTFS
RunAsTI
Launch processes with TrustedInstaller privilege
SetMace
Manipulate timestamps on NTFS
UsnJrnl2Csv
Parser for $UsnJrnl on NTFS
jschicht's Repositories
jschicht/RunAsTI
Launch processes with TrustedInstaller privilege
jschicht/RawCopy
Commandline low level file extractor for NTFS
jschicht/Mft2Csv
Extract $MFT record info and log it to a csv file.
jschicht/LogFileParser
Parser for $LogFile on NTFS
jschicht/UsnJrnl2Csv
Parser for $UsnJrnl on NTFS
jschicht/ExtractUsnJrnl
Tool to extract the $UsnJrnl from an NTFS volume
jschicht/SetMace
Manipulate timestamps on NTFS
jschicht/EaTools
Analysis and manipulation of extended attribute ($EA) on NTFS
jschicht/Indx2Csv
An advanced parser for INDX records
jschicht/PowerMft
Powerful commandline $MFT record editor.
jschicht/SectorIo
Kernel mode driver for writing to physical disk with SL_FORCE_DIRECT_WRITE
jschicht/Secure2Csv
Decode security descriptors in $Secure on NTFS
jschicht/NtfsFileExtractor
Extract files off NTFS
jschicht/MftCarver
Carve $MFT records from a chunk of data (for instance a memory dump)
jschicht/HideAndProtect
Makes files super hidden on NTFS
jschicht/StegoMft
PoC for hiding data within $MFT
jschicht/MftRcrd
Command line $MFT record decoder
jschicht/UsnJrnlCarver
Carving Usn pages (UsnJrnl records)
jschicht/IndxCarver
Carve INDX records from a chunk of data.
jschicht/RcrdCarver
Carve RCRD records ($LogFile) from a chunk of data.
jschicht/ExtractAllAttributes
Extracts all attributes of files on NTFS
jschicht/MakeContainer
Tools to create special containers for patched VeraCrypt/TrueCrypt
jschicht/MakeImage
Create graphic bitmap from binary data.
jschicht/HexDump
Dump binary data to console from file or disk
jschicht/PartDump
Utility to dump basic volume information from a disk object.
jschicht/RawDir
A low level dir command for NTFS volumes
jschicht/Tiny_NTFS
Smallest possible size of a NTFS partition
jschicht/VeraCrypt
Tweaked version for supporting arbitrary offsets.
jschicht/Volsnap-Bug-Content
Content for a volsnap.sys bug analysis
jschicht/MftRef2Name
Resolve file index number to name or vice versa on NTFS