This is the personal website of Willi Ballenthin. I am a consultant at Mandiant, specializing in incident response and computer forensics. Below, you’ll find an index of my public projects. Please feel encouraged to contact me via the link to your left.
- python-registry - A pure Python interface to parsing and reading Windows Registry files.
- python-evtx - A pure Python interface to parsing recent Windows Event Log files (.evtx files).
- NTFS INDX Attribute Parsing - I wrote a tool to easily extract file entries from NTFS directory indices.
- Windows Registry Shellbag Parsing - I wrote a tool to parse Windows shellbag entries into the Bodyfile format.
- Tor - I’ve not contributed to Tor, but this webapp tracks Tor endpoints active over time.
- Windows ReFS File System - I’ve dug into the on-disk structure of the ReFS file system soon.
- The Sleuth Kit - I developed patches bringing basic Ext4 support to the Sleuthkit file system tools.
- Windows Event Log Record Carving - I developed the script LfLe.py to recover Windows EVT event log records from a forensic image.
- log2timeline - I submitted modules to the supertimelining tool, including the Apache2, Syslog, and Analog input modules.
- Analog & Forensics - I successfully used the Analog web log analyzer cache file during a forensic investigation and described my usage.
- list-mft User Defined Formatting February 08, 2014
- Towards better tools: Part 2 February 08, 2014
- Towards better tools: Part 1 February 07, 2014
- Tool Release: fuse-mft January 16, 2014
- Tool Release: list-mft January 15, 2014
- Tool Release: get-file-info January 13, 2014
- Upcoming Tool Releases January 13, 2014
- How to install the Python package manager pip January 11, 2014
- MFT Analysis Presentation December 13, 2013
- Updated ReFS Documentation October 15, 2013
- WIP: Running Autopsy 3 on Linux August 06, 2013
- April Fool’s: TSK and the Registry April 01, 2013
- Building Log2Timeline 0.65 on Ubuntu from Source March 20, 2013
- XMonad and PyCharm March 20, 2013
- [Archives] [atom.xml]