$MFT parser (from live systems or a copy of the $MFT) and raw file copy utility
☆38Jul 18, 2024Updated last year
Alternatives and similar repositories for mftf
Users that are interested in mftf are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- A command-line tool and Python library for parsing Windows Master File Table ($MFT) and importing the results into Elasticsearch.☆13Jun 3, 2026Updated 3 weeks ago
- Forensic cheatsheets for use with cheat☆15Dec 2, 2021Updated 4 years ago
- Get-MiniTimeline - Triage Collection and Timeline Generation w/ KAPE☆35May 25, 2024Updated 2 years ago
- Parses RecentFileCacheParser.bcf files☆31Apr 30, 2026Updated 2 months ago
- A repo for centralizing ongoing research on the new Windows 10/11 DFIR artifact, EventTranscript.db.☆43Jul 18, 2022Updated 3 years ago
- End-to-end encrypted cloud storage - Proton Drive • AdSpecial offer: 40% Off Yearly / 80% Off First Month. Protect your most important files, photos, and documents from prying eyes.
- Carve file metadata from NTFS index ($I30) attributes☆73May 25, 2026Updated last month
- extract and parse WEVT_TEMPLATEs from PE files☆18Dec 30, 2023Updated 2 years ago
- ircollect☆31Aug 7, 2013Updated 12 years ago
- Information about the open-source-dfir slack community