EricRZimmerman
187,985
Downloads of Packages
Packages:
This user has a large number of packages. For performance reasons we are not going to display the package icons below.
A single package that installs all of Eric Zimmerman's forensic tools
geolocate ip addresses in IIS logs
X-Ways Forensics Installation Manager
ShellBags Explorer allows for visually viewing and interacting with shell bags found in usrclass.dat and ntuser.dat Registry hives
Fast, multi-threaded file hashing utility
GUI SDB parser
GUI jumplist parser with Windows 10 support
Timeline Explorer allows for viewing a wide range of CSV files such as plaso/log2timeline and fls/mactime generated timelines. It can also open any CSV or Excel file.
Registry Explorer is a Windows Registry analysis tool with a ton of functionality not found anywhere else
Windows Recycle Bin artifact parser
bstrings is a better strings utility
Amcache.hve parser
Command line jumplist parser with Windows 10 support
lnk (Windows shortcut) parser
Windows prefetch parser
AppCompatCache aka shimcache parser
Windows Volume Shadow Copy mounting tool
TimeApp displays the current and UTC times with millisecond precision
NTFS MFT parser
Windows 10 Timeline database parser