mftmactime

NTFS analyzer

Analyzes and processes NTFS file system data to extract timeline information and run YARA rules for malware detection.

MFT and USN parser that allows direct extraction in filesystem timeline format (mactime), dump all resident files in the MFT in their original folder structure and run yara rules over them all.

GitHub

12 stars
2 watching
2 forks
Language: Python
last commit: over 3 years ago
Linked from 1 awesome list

forensics-toolsmftntfsntfs-adsntfs-journalpython

Backlinks from these awesome lists:

Related projects:

RepositoryDescriptionStars
thewhiteninja/ntfstoolA forensic tool for analyzing NTFS volumes and decrypting encrypted files485
mitre/multiscannerAutomated file analysis framework with modular design and distributed workflow618
msuhanov/dfir_ntfsA digital forensics tool for parsing and analyzing NTFS/FAT file systems.196
aarsakian/mftextractorTool to parse and extract information from NTFS Master File Table (MFT) files.14
williballenthin/python-ntfsA Python library for analyzing and working with NTFS file systems.81
k-sec-tools/yarafilecheckerlibA YARA-based library to analyze files and archives for potential maliciousness2
evild3ad/memprocfs-analyzerAutomated tool for forensic analysis of Windows memory dumps555
xplico/xplicoAnalyzes network traffic data from captured packets to extract and decode specific protocols and information.183
poorbillionaire/usn-journal-parserA Python script to parse the NTFS USN journal and extract metadata changes for forensic analysis.108
xumeiquer/yara-forensicsA set of Yara rules for forensic file analysis135
usualsuspect/malscanA tool to detect and analyze malicious code in process memory by executing Python scripts on YARA matches12
n0fate/volafoxA memory analysis toolkit for macOS developed in Python166
lprat/static_file_analysisAnalyzes files to detect malware and extract embedded content49
ydkhatri/mac_aptA digital forensics tool for analyzing macOS and iOS systems790
sambaranban/fscnmfProvides code and data support for FSCNMF, a network representation technique.2