diff --git a/README.md b/README.md index 7ef608c..a0e2762 100644 --- a/README.md +++ b/README.md @@ -854,6 +854,10 @@ My curated list of awesome links, resources and tools This is a GUI (for Windows 64 bit) for a procedure to virtualize your EWF(E01), DD(Raw), AFF disk image file without converting it, directly with VirtualBox, forensically proof. + + williballenthin/INDXParse + Tool suite for inspecting NTFS artifacts + nshalabi/SysmonTools