
analyzeMFT
analyzeMFT.py is designed to fully parse the MFT file from an NTFS filesystem and present the results as accurately as possible in multiple formats.
data-recoverydigital-forensicsdisk-forensics+1
532

analyzeMFT.py is designed to fully parse the MFT file from an NTFS filesystem and present the results as accurately as possible in multiple formats.

Collect, Process, and Hunt with host based data from MacOS, Windows, and Linux

A really good DFIR automation for collecting and analyzing evidence designed for cybersecurity professionals.