libfsntfs Logo

libfsntfs

0
Free
Visit Website

libfsntfs is a library to access the Windows New Technology File System (NTFS) format. It supports read-only access to NTFS versions 3.0 and 3.1, with features like LZNT1 compression, Windows Overlay Filter (WOF) compressed data, and case sensitive directories. The library is licensed under LGPLv3+ and is currently in an experimental status. For more information, see the project documentation and building instructions on the GitHub wiki.

FEATURES

ALTERNATIVES

Forensic imaging program with full hash authentication and various acquisition options.

Easy-to-use live forensics toolbox for Linux endpoints with various capabilities such as process inspection, memory analysis, and YARA scanning.

A library and set of tools for accessing and analyzing storage media devices and partitions for forensic analysis and investigation.

A forensic analysis tool that extracts and parses logs, notifications, and system information from iOS/iPadOS devices and backups.

A forensic research tool for gathering forensic traces on Android and iOS devices, supporting the use of public indicators of compromise.

View physical memory as files in a virtual file system for easy memory analysis and artifact access.

A powerful reverse engineering framework

A free, open source collection of tools for forensic artifact and image analysis.