Windows forensics Engine
-
Updated
Sep 6, 2026 - Python
Windows forensics Engine
PowerShell Script to facilitate the processing of SRUM data for on-the-fly forensics and if needed threat hunting
Fix the Windows SRUM/SRUJet ESENT event log flood (ESENT 483, 488, 413, 490) safely - one folder ACL, not the dangerous 'Everyone owns C:\Windows' advice
Cross-platform GUI, CLI and MCP server for Microsoft ESE databases (ntds.dit, SRUDB.dat, Exchange .edb, WebCacheV01.dat, Windows.edb) - digital forensics tool with multi-format extract and reporting
See exactly what Windows tracks, logs, and stores about you — GDID, SRUM, UserAssist & more. Local-first, open source
Single-file HTA GUI for triaging Windows SRUM (System Resource Usage Monitor) with Eric Zimmerman's SrumECmd - DFIR data-exfiltration hunting.
SRUM forensics: prove whether a human was at the keyboard. Parse SRUDB.dat on Linux/macOS. Detect malware, exfiltration, and automated execution. Single static Rust binary.
A fast, cross-artifact Windows forensic timeline correlator in Python. Automatically stitches fragmented telemetry from MFT, SRUM, Shimcache, and BAM to spot timestomping, ghost execution, and account-level activity in one unified timeline.
To associate your repository with the srum topic, visit your repo's landing page and select "manage topics."