File System
Extracts entries that Windows marks as excluded from Volume Shadow Copy Service (VSS) and backup operations, from the
System hiveRegistry
Parse the
GetThis files produced by Orc and retrieve information about the collected filesGetThis
Extracts information about every USB (or other) mass‑storage device ever connected to a Windows system, using data from the
System hiveRegistry
Reads a text file and concatenates every line into a single output line
Merge
Extract NTFS’s Master File Table (MFT) from an ORC‑generated CSV file
NTFSInfo
Extracts entries from the
PendingFileRenameOperations value in the System hiveRegistry
Extracts metadata from Windows recycle‑bin files
RecycleBin
Extracts the contents of Shell Bag structures stored in the
UsrClass hiveRegistry
Srum table for windows server 2022 that tracks physical drive information
Srum
Srum table for windows server 2022 that tracks storage volumes information
Srum
Parses the CSV export of the Windows USN Journal
USNInfo
Parses a Windows volume‑statistics csv file
Csv
Parses CSV files that list Volume Shadow Copy (VSS) snapshots
Csv