Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
ntfstool — Forensics tool for NTFS (parser, mft, bitlocker, deleted files) | Kitploit
Tools/GitHubGitHub/thewhiteninja/ntfstool
Disk ForensicsEncryption/Decryption ToolsVulnerability AnalysisForensicsData RecoveryDigital Forensics
GitHubthewhiteninja/ntfstool

ntfstool

Forensics tool for NTFS (parser, mft, bitlocker, deleted files)

View Repository
620116283 months agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

ntfstool

GitHub license Language: C++ x64 x86 v1.6 Build


NTFSTool is a forensic tool focused on NTFS volumes. It supports reading partition info (MBR, partition table, VBR) but also information on Master File Table, Bitlocker encrypted volume, EFS encrypted files, USN journal and more.

Download the latest binaries on AppVeyor or by checking the last GitHub artefacts.

See below for some examples of the features!

An alternative documentation made by deepwiki is available here : https://deepwiki.com/thewhiteninja/ntfstool/

Features

Forensics

NTFSTool displays the complete structure of master boot record, volume boot record, partition table and $MFT file record. It is also possible to dump any file (even $MFT or SAM) or parse and analyze USN journal, LogFile including streams from Alternate Data Stream (ADS). $MFT can be dumped as csv or json with Zone.Identifier parsing to quickly identify downloaded files. The undelete command will search for any file record marked as "not in use" and allow you to retrieve the file (or part of the file if it was already rewritten). It support input from image file, live disk or virtual like VeraCrypt and TrueCrypt, but you can also use tools like OSFMount to mount your disk image. Sparse and compressed files (lznt1, xpress) are also supported.

Bitlocker support

For bitlocked partition, it can display FVE records, check a password and key (bek, password, recovery key), extract VMK and FVEK. There is no bruteforce feature because GPU-based cracking is better (see Bitcracker and Hashcat) but you can get the hash for these tools.

EFS support

Masterkeys, private keys and certificates can be listed, displayed and decrypted using needed inputs (SID, password). Certificates with private keys can be exported using the backup command.

Reinmport the backup on another machine to be able to read your encrypted file again! Or you can use the efs.decrypt command to decrypt a file using the backed-up key.

More information on Mimikatz Wiki

USN Journal analysis

USN journal records can be analyzed using custom rules to detect suspicious programs and actions but also to have an overview of the journal (% of file deleted, created ...)

Default rules: Rules/default.json

  {
    "id": "lsass-dump",
    "description": "Dumped LSASS.exe process.",
    "severity": "high",
    "rule": {
      "filename": "lsass(\\.(dmp|dump))?"
    }
  }

See an example of run here: usn.analyze

Shell

There is a limited shell with few commands (exit, cd, ls, cat, pwd, cp, quit, rec).

Command rec shows the MFT record details.

Help & Examples

Help command displays description and examples for each command.

Options can be entered as decimal or hex number with "0x" prefix (ex: inode).

ntfstool help [command]
CommandDescription
infoDisplay information for all disks and volumes
mbrDisplay MBR structure, code and partitions for a disk
gptDisplay GPT structure, code and partitions for a disk
vbrDisplay VBR structure and code for a specidifed volume (ntfs, fat32, fat1x, bitlocker supported)
extractExtract a file from a volume.
imageCreate an image file of a disk or volume.
mft.dumpDump $MFT file in specified format: csv, json, raw.
mft.recordDisplay FILE record details for a specified MFT inode. Almost all attribute types supported
mft.btreeDisplay VCN content and Btree index for an inode
bitlocker.infoDisplay information and hash ($bitlocker$) for all VMK. Test a password or recovery key.
bitlocker.decryptDecrypt a volume to a file using password, recovery key or bek.
bitlocker.fveDisplay information for the specified FVE block.
efs.backupExport EFS keys in PKCS12 (pfx) format.
efs.decryptDecrypt EFS encrypted file using keys in PKCS12 (pfx) format.
efs.certificateList, display and export system certificates (SystemCertificates/My/Certificates).
efs.keyList, display, decrypt and export private keys (Crypto/RSA).
efs.masterkeyList, display and decrypt masterkeys (Protect).
reparseParse and display reparse points from $Extend$Reparse.
logfile.dumpDump $LogFile file in specified format: csv, json, raw.
usn.analyzeAnalyze $UsnJrnl file with specified rules. Output : csv or json.
usn.dumpDump $UsnJrnl file in specified format: csv, json, raw.
shadowList volume shadow snapshots from selected disk and volume.
streamsDisplay Alternate Data Streams
undeleteSearch and extract deleted files for a volume.
shellStart a limited Unix-like shell
smartDisplay S.M.A.R.T data

Limitations

  • Some unsupported cases. WIP.
  • No documentation 😶.

Feel free to open an issue or ask for a new feature!

Build

  • Install Visual Studio 2022

  • Install vcpkg (for required third-party libs) as described here: vcpkg#getting-started

    git clone https://github.com/microsoft/vcpkg
    .\vcpkg\bootstrap-vcpkg.bat
    
  • Integrate it to your VisualStudio env:

    vcpkg integrate install
    

At build time, VisualStudio will detect the vcpkg.json file and install required packages automatically.

Download Tool