Skip to content

janstarke/dfir-esedb

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

8 Commits
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

dfir-esedb

This crate provides a parser for Microsofts EseDB files, aimed to be used for forensic purposes.

Usage Example

use std::path::PathBuf;
use dfir_esedb::EseDb;
let db = EseDb::open(&PathBuf::from("tests/data/ntds_plain.dit")).unwrap();

assert_eq!(db.header().database_time().hours(), &21);
assert_eq!(db.header().database_time().minutes(), &45);
assert_eq!(db.header().database_time().seconds(), &2);

About

A library to allow forensic analysis of EseDB files

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages