libfsntfs Logo

libfsntfs

0
Free
Visit Website

libfsntfs is a library to access the Windows New Technology File System (NTFS) format. It supports read-only access to NTFS versions 3.0 and 3.1, with features like LZNT1 compression, Windows Overlay Filter (WOF) compressed data, and case sensitive directories. The library is licensed under LGPLv3+ and is currently in an experimental status. For more information, see the project documentation and building instructions on the GitHub wiki.

FEATURES

ALTERNATIVES

A free, open source collection of tools for forensic artifact and image analysis.

A file search and query tool for ops and security experts.

A tool for triaging crash files with various output formats and debugging engine options.

Dump iOS Frequent Locations from StateModel#.archive files.

Rekall is a discontinued project that aimed to improve memory analysis methodology but faced challenges due to the nature of in-memory structure and increasing security measures.

Windows event log fast forensics timeline generator and threat hunting tool.

MalConfScan is a Volatility plugin for extracting configuration data of known malware and analyzing memory images.

A script to assist in creating templates for VirtualBox to enhance VM detection evasion.

PINNED