{"repo":"cristianzsh/amcache-evilhunter","free":true,"listed":false,"github":"https://github.com/cristianzsh/amcache-evilhunter","clone":"git clone https://github.com/cristianzsh/amcache-evilhunter.git","description":"Parse and analyze a Windows Amcache.hve registry hive, VirusTotal integration.","language":"Python","stars":114,"topics":["amcache","automation","dfir","forensics","incident-response","malware","malware-detection"],"license":"MIT","category":"workflow-automation","readme_excerpt":"AmCache-EvilHunter AmCache-EvilHunter is a command-line tool to parse and analyze Windows Amcache.hve registry hives, identify evidence of execution, suspicious executables, and integrate VirusTotal/OpenTIP lookups for enhanced threat intelligence. https://github.com/user-attachments/assets/e23fb99b-48ad-4260-b372-2f15e5320c74 Features Parse offline Amcache.hve registry hives. Filter records by date range ( --start , --end ). Search records using keywords ( --search ). Identify known suspicious executables ( --find-suspicious ). Identify executables without a publisher ( --missing-publisher ). Kaspersky OpenTIP integration for hash lookups ( --opentip , --only-detections ). VirusTotal integration for hash lookups ( --vt , --only-detections ). Export results to JSON ( --json ) or CSV ( --csv ). Requirements Python 3.7 or higher requests python-registry rich Install dependencies via pip : Installation Usage Options Flag Description -------------------- -------------------------------------------------------------------------- -i , --input PATH Path to Amcache.hve (required) --start YYYY-MM-DD Only include records on or after this date --end YYYY-MM-DD Only include records on or before this date --search TERMS Comma-separated, case-insensitive search terms --find-suspicious Filter only records matching known suspicious patterns --missing-publisher Filter only records with missing Publisher --exclude-os Only include non-OS-component files --opentip Enable Kaspersky OpenTIP lookup","default_branch":null,"files":null,"tree":[],"storefront":"/r/cristianzsh","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/cristianzsh/amcache-evilhunter/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}