This is the personal website of Willi Ballenthin. I am a reverse engineer with a background in incident response and computer forensics. Below, you’ll find an index of my public projects. Please feel encouraged to contact me via the link to your left.
- python-registry - A pure Python interface to parsing and reading Windows Registry files.
- python-evtx - A pure Python interface to parsing recent Windows Event Log files (.evtx files).
- NTFS INDX Attribute Parsing - I wrote tools for forensic analysis of NTFS file systems, including a utility to easily extract file entries from NTFS directory indices.
- Windows Registry Shellbag Parsing - I developed a tool to parse Windows shellbag entries into the Bodyfile format.
- Tor - I’ve not contributed to Tor, but this webapp tracks Tor endpoints active over time.
- Windows Event Log Record Carving - I published the script LfLe.py to recover Windows EVT event log records from a forensic image.
- WMI forensics - At FireEye, we reverse engineered the WMI CIM repository file format and developed tools to enable forensic analysis.
- Application Compatibility Infrastructure Analysis - Since the file format for “shim databases” (.sdb files) was undocumented, I reverse engineered the format and published a parsing library in Python.
- Recent projects September 02, 2015
- RegRipper on Linux April 02, 2014
- list-mft User Defined Formatting February 08, 2014
- Towards better tools: Part 2 February 08, 2014
- Towards better tools: Part 1 February 07, 2014
- Tool Release: fuse-mft January 16, 2014
- Tool Release: list-mft January 15, 2014
- Tool Release: get-file-info January 13, 2014
- Upcoming Tool Releases January 13, 2014
- How to install the Python package manager pip January 11, 2014
- MFT Analysis Presentation December 13, 2013
- Updated ReFS Documentation October 15, 2013
- WIP: Running Autopsy 3 on Linux August 06, 2013
- April Fool’s: TSK and the Registry April 01, 2013
- Building Log2Timeline 0.65 on Ubuntu from Source March 20, 2013
- XMonad and PyCharm March 20, 2013
- [Archives] [atom.xml]