±Your Account
Membership:
New Today: 0
New Yesterday: 4
Overall: 24360
Visitors: 32±Latest Articles
· Catching the ghost: how to discover ephemeral evidence with Live RAM analysis
· Geo-tagging & Photo Tracking On iOS
· KS – an open source bash script for indexing data
· Mobile Device Geotags & Armed Forces
· Categorization of embedded system forensic collection methodologies
· Interpretation of NTFS Timestamps
· What are ‘gdocs’? Google Drive Data – part 2
· What are ‘gdocs’? Google Drive Data
· Bad Sector Recovery
· Forensic Artifact: Malware Analysis in Windows 8
· Geo-tagging & Photo Tracking On iOS
· KS – an open source bash script for indexing data
· Mobile Device Geotags & Armed Forces
· Categorization of embedded system forensic collection methodologies
· Interpretation of NTFS Timestamps
· What are ‘gdocs’? Google Drive Data – part 2
· What are ‘gdocs’? Google Drive Data
· Bad Sector Recovery
· Forensic Artifact: Malware Analysis in Windows 8
±Follow Us
±Latest Jobs
Back to top
Skip to content
Skip to menu
Back to top
Back to main
Skip to menu
Go to page 1, 2 Next
Introducing Simple File Parser v1.2.1
Introducing Simple File Parser v1.2.1
Posted: Fri Mar 30, 2012 12:54 pm
Hi All,
I'm currently writing a tool for the parsing of common Windows artefacts and I would like to share it with the forensic community. This tool is called the Simple File Parser (SFP) and it currently supports the parsing of link and prefetch files and allows the user to easily export the information to CSV format for a more detailed analysis.
To take a look at the program or to download it yourself, please visit the tool's blog page: simplefileparser.blogspot.co.uk/. You will need .NET 4 installed before running this program.
I will take on-board any comments, or if you find any bugs please let me know.
Chris.
I'm currently writing a tool for the parsing of common Windows artefacts and I would like to share it with the forensic community. This tool is called the Simple File Parser (SFP) and it currently supports the parsing of link and prefetch files and allows the user to easily export the information to CSV format for a more detailed analysis.
To take a look at the program or to download it yourself, please visit the tool's blog page: simplefileparser.blogspot.co.uk/. You will need .NET 4 installed before running this program.
I will take on-board any comments, or if you find any bugs please let me know.
Chris.
-

chrism - Senior Member
Re: Introducing Simple File Parser v1.2.1
Posted: Sun Apr 15, 2012 1:07 pm
Version 1.3 has been released and has initial support for Windows 7 jump-lists.
-

chrism - Senior Member
Re: Introducing Simple File Parser v1.2.1
Posted: Mon Apr 16, 2012 3:39 pm
Thanks for this great tool.
Thierry
Thierry
-

tg92 - Member
Re: Introducing Simple File Parser v1.2.1
Posted: Wed Apr 18, 2012 2:04 am
Thanks Thierry, I have plans to improve the jump-list support and to make it multi-threaded for performance (once I've worked out how to thread in C# that is!).
-

chrism - Senior Member
Simple File Parser v1.4
Posted: Fri Jun 15, 2012 5:47 am
Version 1.4 has now been released with more robust support for jump-list artefacts, improved GUI and speed, multithreaded goodness and multiple time-zone support. Download at www.simplefileparser.blogspot.com.
As ever, please let me have your comments and suggestions for future releases.
As ever, please let me have your comments and suggestions for future releases.
-

chrism - Senior Member
Re: Introducing Simple File Parser v1.5
Posted: Wed Nov 21, 2012 7:47 am
Version 1.5 now has support for the parsing of INDX Attributes ($I30 files).
Let me know if you have any issues.
Let me know if you have any issues.
-

chrism - Senior Member
Re: Introducing Simple File Parser v1.2.1
Posted: Wed Nov 21, 2012 8:31 am
Does the LNK parser support parsing the shell item ID lists?
-

keydet89 - Senior Member
















