MFTExtractor Logo

MFTExtractor

0
Free
Visit Website

A Parser of Master File Table NTFS file system. Using this tool you can explore $MFT NTFS and its file system attributes. You can selectively extract filesystem information of record or for a range of records. In addition, you can export the contents of files. Exporting files can be achieved either by mounting the evidence and providing its physical drive order and partition number or by using the acquired forensic image (Expert Witness Format), or virtual machine disk format. Examples you can now explore NTFS by providing physical drive number and partition number e.g. -physicaldrive 0 -partition 1 translates to \.\

FEATURES

ALTERNATIVES

A powerful reverse engineering framework

iOS Mobile Backup Xtractor tool for extracting iOS backups.

A library to access FileVault Drive Encryption (FVDE) encrypted volumes on Mac OS X systems.

Dissect is a digital forensics & incident response framework that simplifies the analysis of forensic artefacts from various disk and file formats.

Developing APIs to access memory on industrial control system devices.

Advanced computer forensics software with efficient features.

A collection of PowerShell modules for artifact gathering and reconnaissance of Windows-based endpoints.

Toolkit for performing acquisitions on iOS devices with logical and filesystem acquisition support.

PINNED