EVTXtract recovers and reconstructs fragments of EVTX log files from raw binary data, including unallocated space and memory images.
APACHE-2.0 License
A collection of utilities to help with analysis on the command line.
Reconstruct process trees from event logs
Recover event log entries from an image by heurisitically looking for record structures.
Pure Python parser for Windows Event Log files (.evtx)
volatility explorer
Query and report user logons relations from MS Windows Security Events
An advanced memory forensics framework
Volatility Plugins
Interactively find and recover deleted or overwritten files from your terminal
Dshell is a network forensic analysis framework.