Skip to content

extracting boot times from a windows machine from the bootstat.dat

Notifications You must be signed in to change notification settings

hakkabara/extract-bootstat

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

8 Commits
 
 
 
 
 
 
 
 
 
 

Repository files navigation

extract-bootstat

This tool extract boot times from a Microsoft Windows Machine for IR/DFIR (Forensics) by parsing the bootstat.dat which is located in C:\Windows\bootstat.dat.

This Project is inspired by PSBits/Extract-BootTimes.ps1. The main reason for rewriting this in Rust is I don't like to work with winblows and get started in using Rust.

usage


About

extracting boot times from a windows machine from the bootstat.dat

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages