MFTMactime Logo

MFTMactime

0
Free
Visit Website

This is an MFT and USN parser that allows direct extraction in filesystem timeline format (mactime), dump all resident files in the MFT in their original folder structure and run yara rules over them all. It uses Omer BenAmram's great MFT rust parsing libraries, which allows a great speed and efficiency in the process. The integration with the USN Journal parser allows to have in the same timeline the combined MFT and USN data. You can use as input files either individual files derived from a triage or a forensic image in RAW format or a mixture of both modes. In case the input is RAW the artifacts will be dumped in a selected directory.

FEATURES

ALTERNATIVES

A library to access the Expert Witness Compression Format (EWF) for digital forensics and incident response.

Create checkpoint snapshots of the state of running pods for later off-line analysis.

A tool for extracting files from packet capture files with ease of use and extensibility for Python developers.

Comprehensive suite for advanced file analysis and software supply chain security.

Open source digital forensics tools for analyzing disk images and recovering files.

Toolkit for post-mortem analysis of Docker runtime environments using forensic HDD copies.

Anti-forensics tool for Red Teamers to erase footprints and test incident response capabilities.

CyLR is a Live Response Collection tool for quickly and securely collecting forensic artifacts from hosts with NTFS file systems.

PINNED