
analyzeMFT
analyzeMFT.py is designed to fully parse the MFT file from an NTFS filesystem and present the results as accurately as possible in multiple formats.
data-recoverydigital-forensicsdisk-forensics+1
533

analyzeMFT.py is designed to fully parse the MFT file from an NTFS filesystem and present the results as accurately as possible in multiple formats.

CLI and interactive console for listing, browsing, and extracting files from VM disk images (VHDX, VMDK, EBS snapshots, raw disks) for red-team…


A really good DFIR automation for collecting and analyzing evidence designed for cybersecurity professionals.

Python script for carving Bitlocker VMK keys

Digital Forensics Intelligence Framework