dfir_ntfs
by msuhanov
An NTFS/FAT parser for digital forensics & incident response
AI summary
File system analyzer
A digital forensics tool for parsing and analyzing NTFS/FAT file systems.
- stars
- 196
- forks
- 30
- watching
- 21
Similar projects
Found by comparing what the projects do, not just their names.
NTFS parser
A Dissect module implementing a parser for the NTFS file system used by Windows operating systems
NTFS analyzer
A forensic tool for analyzing NTFS volumes and decrypting encrypted files
arxsys/dff276
Forensic tool
A framework for automating digital forensic analysis and incident response
Forensic Viewer
A graphical user interface for viewing and analyzing files and volumes in a forensic context
Forensic analyzer
A digital forensics tool for analyzing macOS and iOS systems
NTFS analyzer
Analyzes and processes NTFS file system data to extract timeline information and run YARA rules for malware detection.
Windows forensic tool
A digital forensic tool designed to gather and analyze data from Windows-based systems in incident response scenarios.
NTFS parser
A tool suite for parsing NTFS artifacts and extracting information from INDX files.
Forensic parser
A Python-based tool for parsing and analyzing Windows Defender's DetectionHistory forensic artifact.
Forensics setup
A suite of tools and images for building and managing digital forensics environments on AWS
Forensic analysis toolset
A digital forensics framework that provides tools and parsers to analyze forensic artefacts from various disk and file formats.
Malware analyzer
Tool to analyze files during malware analysis and triage by extracting properties and detecting malicious indicators.
File scanner
Tools for detecting suspicious files and directories on Windows and Linux endpoints.
Metadata extractor
A Python script to parse the NTFS USN journal and extract metadata changes for forensic analysis.
File system parser
A Dissect module implementing parsers for FAT and exFAT file systems.