
analyzeMFT
analyzeMFT.py is designed to fully parse the MFT file from an NTFS filesystem and present the results as accurately as possible in multiple formats.
data-recoverydigital-forensicsdisk-forensics+1
532

analyzeMFT.py is designed to fully parse the MFT file from an NTFS filesystem and present the results as accurately as possible in multiple formats.

A really good DFIR automation for collecting and analyzing evidence designed for cybersecurity professionals.

Collect, Process, and Hunt with host based data from MacOS, Windows, and Linux