ntfstool

NTFS analyzer

A forensic tool for analyzing NTFS volumes and decrypting encrypted files

Forensics tool for NTFS (parser, mft, bitlocker, deleted files)

GitHub

485 stars
23 watching
98 forks
Language: C++
last commit: about 3 years ago
bitlockerbtreecompresseddiskefsfvegptlogfilembrmftntfsparserreparsesmartsparseundeleteusnvbrvmkvss

Related projects:

RepositoryDescriptionStars
williballenthin/python-ntfsA Python library for analyzing and working with NTFS file systems.81
msuhanov/dfir_ntfsA digital forensics tool for parsing and analyzing NTFS/FAT file systems.196
kero99/mftmactimeAnalyzes and processes NTFS file system data to extract timeline information and run YARA rules for malware detection.12
xplico/xplicoAnalyzes network traffic data from captured packets to extract and decode specific protocols and information.183
williballenthin/indxparseA tool suite for parsing NTFS artifacts and extracting information from INDX files.215
nesfit/netfoxdetectiveA network forensic analysis tool that extracts content from communication protocols and visualizes it in various ways38
pjrinaldi/wombatforensicsA multi-threaded GUI forensic analysis tool for Linux48
nachoparker/dutreeA tool to analyze and visualize file system usage in various formats827
fox-it/dissect.ntfsA Dissect module implementing a parser for the NTFS file system used by Windows operating systems8
0x4d31/fattA tool for extracting network metadata and fingerprints from packet capture files or live network traffic.661
antagon/tchunt-ngA tool that uses various tests to identify and analyze encrypted files on a filesystem.52
fox-it/dissect.vmfsA Dissect module parsing VMFS file system structure and layout3
lazza/recuperabitA tool to analyze and reconstruct damaged file systems549
fox-it/dissect.xfsA Dissect module implementing a parser for the XFS file system, commonly used by RedHat Linux distributions.2
aarsakian/mftextractorTool to parse and extract information from NTFS Master File Table (MFT) files.14