MFTExtractor Logo

MFTExtractor

0
Free
Visit Website

A Parser of Master File Table NTFS file system. Using this tool you can explore $MFT NTFS and its file system attributes. You can selectively extract filesystem information of record or for a range of records. In addition, you can export the contents of files. Exporting files can be achieved either by mounting the evidence and providing its physical drive order and partition number or by using the acquired forensic image (Expert Witness Format), or virtual machine disk format. Examples you can now explore NTFS by providing physical drive number and partition number e.g. -physicaldrive 0 -partition 1 translates to \.\

FEATURES

ALTERNATIVES

A software utility with forensic tools for smartphones, offering powerful data extraction and decoding capabilities.

Free software for extracting Microsoft cabinet files, supporting all features and formats of Microsoft cabinet files and Windows CE installation files.

Open Source computer forensics platform with modular design for easy automation and scripting.

Dump the contents of the location database files on iOS and macOS with output options like KML and CSV.

A simple Golang application for storing NIST National Software Reference Library Reference Data Set (NSRL RDS) with md5 and sha1 hash lookup searches.

Educational CTF-styled challenges for Memory Forensics.

A collection of PowerShell modules for artifact gathering and reconnaissance of Windows-based endpoints.

Recover event log entries from an image by heuristically looking for record structures.