This is your work, valued
regf. Windows registry file format specification
366dfir_ntfs. An NTFS/FAT parser for digital forensics & incident response
237Linux-write-blocker. The kernel patch and userspace tools to enable Linux software write blocking
156yarp. Yet another registry parser
139winmem_decompress. Extract compressed memory pages from page-aligned data
47ntfs-samples. NTFS samples
28regf-samples. Windows registry samples
24registry-miner. Registry Miner
14grub-unlzma. Locate and extract a compressed core image within a bootable image of GRUB
8articles. Various files linked to my articles, posts, etc.
6grub-raiddump. The GRUB command to acquire the contents of a fake RAID
4easy_triage. Scripts to triage compromised systems (Linux, ESXi, FreeBSD/NetScaler)
3winbootpath. Boot path verification for Windows on read-only media
1openssh-portable. Portable OpenSSH
1