
analyzeMFT
analyzeMFT.py is designed to fully parse the MFT file from an NTFS filesystem and present the results as accurately as possible in multiple formats.
data-recoverydigital-forensicsdisk-forensics+1
533

analyzeMFT.py is designed to fully parse the MFT file from an NTFS filesystem and present the results as accurately as possible in multiple formats.

A really good DFIR automation for collecting and analyzing evidence designed for cybersecurity professionals.


Collection of forensic tools

A Mac OS X forensic utility which manages file system mounting in support of forensic procedures.

FAT filesystems explore, extract, repair, and forensic tool