Application text logs for forensics: vsftpd, PostgreSQL, Debian popularity-contest, Snort and Suricata fast alerts, Google logging (glog), Santa, macOS…
Windows File History catalogs (Catalog1.edb, Catalog2.edb) for forensics: every file and folder backed up, with its path, times, attributes and USN, and the…
Internet Explorer 4 to 9 cache and history files (index.dat) for forensics: cached URLs with their files and HTTP headers, visited pages, redirects, leaked…
Windows 10/11 notifications (wpndatabase.db) for forensics: toasts, tiles and badges apps raised, with their app, times and visible text, and the apps…
Windows Portable Executable (PE) metadata for forensics: compile time, type, sections, imports, exports, import hash, version information, PDB path, resource…
macOS Spotlight store databases (store.db, .store.db) for forensics: every file Spotlight indexed, with its name, kind, content type and times (added, used,…
The BREP PLM server: parts, revisions, lifecycle, checkout, BOMs and change orders over an embedded SQLite store, with a browser UI and the document API the…
NTFS directory indexes ($I30 INDX records) for forensics: every entry with its $FILE_NAME times and sizes, and the deleted and renamed entries left in index…
Windows Volume Shadow Copies (VSS) in an NTFS volume: every snapshot with its times, GUIDs and machine names, and each snapshot's view of the volume as a Read…
The tabnas language server in Rust: diagnostics, outline, semantic tokens, hover and completion for every tabnas grammar, as a library for Rust hosts and a…