Vault of Windows Registry forensic artifacts
-
Updated
Nov 12, 2025 - JavaScript
Vault of Windows Registry forensic artifacts
AutoParser is a forensic tool for parsing offline registry hives.
Malicious code examples in python (e.g. backdoor, self-replicant code, keylogger, etc.).
High‑performance iocx plugin for detecting Windows Registry keys, values, and persistence locations. Includes full test coverage, performance benchmarks, and security checks.
Pulls select event logs, firewall rules, and registry keys from windows machines into .csv files via powershell.
Add a description, image, and links to the registry-keys topic page so that developers can more easily learn about it.
To associate your repository with the registry-keys topic, visit your repo's landing page and select "manage topics."