collection of structs and utilities for parsing windows binary formats.
A Rust parser for Windows Jumplist artifact
A Rust parser for Notepad TabState artifact
Rhaegal is a tool used to scan Windows Event Logs for suspicious logs. Rhaegal uses custom rule format to detect suspicious/malicious logs