
Skadi
Collect, Process, and Hunt with host based data from MacOS, Windows, and Linux
curated-resourcesdigital-forensicsdisk-forensics+9
518

Collect, Process, and Hunt with host based data from MacOS, Windows, and Linux

analyzeMFT.py is designed to fully parse the MFT file from an NTFS filesystem and present the results as accurately as possible in multiple formats.

A really good DFIR automation for collecting and analyzing evidence designed for cybersecurity professionals.