MFTMactime Logo

MFTMactime

0
Free
Visit Website

This is an MFT and USN parser that allows direct extraction in filesystem timeline format (mactime), dump all resident files in the MFT in their original folder structure and run yara rules over them all. It uses Omer BenAmram's great MFT rust parsing libraries, which allows a great speed and efficiency in the process. The integration with the USN Journal parser allows to have in the same timeline the combined MFT and USN data. You can use as input files either individual files derived from a triage or a forensic image in RAW format or a mixture of both modes. In case the input is RAW the artifacts will be dumped in a selected directory.

FEATURES

ALTERNATIVES

PowerForensics is a PowerShell digital forensics framework for hard drive forensic analysis.

Diffy is a digital forensics and incident response (DFIR) tool developed by Netflix's Security Intelligence and Response Team (SIRT) for scoping compromises across cloud instances.

Create checkpoint snapshots of the state of running pods for later off-line analysis.

Forensic imaging program with full hash authentication and various acquisition options.

View physical memory as files in a virtual file system for easy memory analysis and artifact access.

Tool for analyzing Windows Recycle Bin INFO2 file

A collection of PowerShell modules for artifact gathering and reconnaissance of Windows-based endpoints.

Orochi is a collaborative forensic memory dump analysis framework.

PINNED