How this analysis was created: This summary and feature list were written by an AI model that read the project's README and public documentation pages. Each feature links to the documentation it came from; stars, license and language come straight from the GitHub API. The model does not read the source code, and the analysis is refreshed when the project is re-analysed. Learn more on our About page.
Open source Python library for NTFS analysis
The main features of williballenthin/python-ntfs are: Windows Artifact Analysis, File System Processing.
Open-source alternatives to williballenthin/python-ntfs include: thewhiteninja/ntfstool — Forensics tool for NTFS (parser, mft, bitlocker, deleted files). poorbillionaire/usn-journal-parser — Python script to parse the NTFS USN Journal. lazza/recuperabit. abrignoni/dfir-sql-query-repo — Collection of SQL queries templates for digital forensics use by platform and application. These queries are templates… forensicartifacts/artifacts — Digital Forensics artifact repository. cgosec/blauhaunt — A tool collection for filtering and visualizing logon events. Designed to help answering the "Cotton Eye Joe" question…
Python script to parse the NTFS USN Journal
Forensics tool for NTFS (parser, mft, bitlocker, deleted files)
Collection of SQL queries templates for digital forensics use by platform and application. These queries are templates that should be edited based on the needs of the analyst. Many of these queries will have an accompanying README with a link for more detailed explanations on usage and possible…