awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
thewhiteninja avatar

thewhiteninja/ntfstool

0
View on GitHub↗
617 stars·116 forks·C++·MIT·7 views

Ntfstool

Forensics tool for NTFS (parser, mft, bitlocker, deleted files)

Features

  • Databases & Data - Forensics tool for NTFS.
  • Windows Artifact Analysis - Comprehensive tool for NTFS forensic analysis.
  • Forensics and Incident Response - Forensic tool for NTFS analysis and recovery.
  • File System Processing - Tool for NTFS forensic analysis.

Star history

Star history chart for thewhiteninja/ntfstoolStar history chart for thewhiteninja/ntfstool

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Start searching with AI

Open-source alternatives to Ntfstool

Similar open-source projects, ranked by how many features they share with Ntfstool.
  • cgosec/blauhauntcgosec avatar

    cgosec/Blauhaunt

    184View on GitHub↗

    A tool collection for filtering and visualizing logon events. Designed to help answering the "Cotton Eye Joe" question (Where did you come from where did you go) in Security Incidents and Threat Hunts

    JavaScript
    View on GitHub↗184
  • forensicartifacts/artifactsForensicArtifacts avatar

    ForensicArtifacts/artifacts

    1,240View on GitHub↗

    Digital Forensics artifact repository

    Python
    View on GitHub↗1,240
  • bsi-bund/rdpcachestitcherBSI-Bund avatar

    BSI-Bund/RdpCacheStitcher

    329View on GitHub↗

    RdpCacheStitcher is a tool that supports forensic analysts in reconstructing useful images out of RDP cache bitmaps. Using raw RDP cache tile bitmaps extracted by tools like e.g. ANSSI's BMC-Tools (https://github.com/ANSSI-FR/bmc-tools) as input, it provides a graphical user interface and…

    C++
    View on GitHub↗329
  • jpcertcc/logontracerJPCERTCC avatar

    JPCERTCC/LogonTracer

    3,136View on GitHub↗

    LogonTracer is a security auditing tool designed for logon analysis and forensic log auditing. It functions as a dockerized security auditor that utilizes a security event graph database to map account names and network addresses, allowing for the visualization of complex system compromise patterns and authentication paths. The system features a Sigma detection engine that scans imported event logs against standardized rule sets to identify known malicious activity. It also includes an anomalous behavior detector that applies statistical analysis, graph algorithms, and hidden Markov models to

    Pythonactive-directoryblueteamdfir
    View on GitHub↗3,136
See all 30 alternatives to Ntfstool→

Frequently asked questions

What does thewhiteninja/ntfstool do?

Forensics tool for NTFS (parser, mft, bitlocker, deleted files)

What are the main features of thewhiteninja/ntfstool?

The main features of thewhiteninja/ntfstool are: Databases & Data, Windows Artifact Analysis, Forensics and Incident Response, File System Processing.

What are some open-source alternatives to thewhiteninja/ntfstool?

Open-source alternatives to thewhiteninja/ntfstool include: forensicartifacts/artifacts — Digital Forensics artifact repository. lazza/recuperabit. bsi-bund/rdpcachestitcher — RdpCacheStitcher is a tool that supports forensic analysts in reconstructing useful images out of RDP cache bitmaps.… cgosec/blauhaunt — A tool collection for filtering and visualizing logon events. Designed to help answering the "Cotton Eye Joe" question… jpcertcc/logontracer — LogonTracer is a security auditing tool designed for logon analysis and forensic log auditing. It functions as a… poorbillionaire/usn-journal-parser — Python script to parse the NTFS USN Journal.