Ecosyste.ms: Awesome

An open API service indexing awesome lists of open source software.

https://github.com/thewhiteninja/ntfstool

Forensics tool for NTFS (parser, mft, bitlocker, deleted files)

bitlocker btree compressed disk efs fve gpt logfile mbr mft ntfs parser reparse smart sparse undelete usn vbr vmk vss

Last synced: 16 Jun 2024

https://github.com/kero99/mftmactime

MFT and USN parser that allows direct extraction in filesystem timeline format (mactime), dump all resident files in the MFT in their original folder structure and run yara rules over them all.

forensics-tools mft ntfs ntfs-ads ntfs-journal python

Last synced: 26 May 2024

https://github.com/AdamWhiteHat/Judge-Jury-and-Executable

A file system forensics analysis scanner and threat hunting tool. Scans file systems at the MFT and OS level and stores data in SQL, SQLite or CSV. Threats and data can be probed harnessing the power and syntax of SQL.

antivirus csharp forensic-analysis forensics forensics-investigations forensics-level-scanning mft query-language scanner security threat-hunting threat-monitor yara yara-rules yara-scanner

Last synced: 01 May 2024

https://github.com/EricZimmerman/MFTECmd

Parses $MFT from NTFS file systems

forensics mft ntfs

Last synced: 02 Apr 2024