How this analysis was created: This summary and feature list were written by an AI model that read the project's README and public documentation pages. Each feature links to the documentation it came from; stars, license and language come straight from the GitHub API. The model does not read the source code, and the analysis is refreshed when the project is re-analysed. Learn more on our About page.
Digital Forensics artifact repository
Python script to parse the NTFS USN Journal
Collection of SQL queries templates for digital forensics use by platform and application. These queries are templates that should be edited based on the needs of the analyst. Many of these queries will have an accompanying README with a link for more detailed explanations on usage and possible…
The main features of abrignoni/dfir-sql-query-repo are: File System Processing.
Open-source alternatives to abrignoni/dfir-sql-query-repo include: aarsakian/mftextractor — FileSystemForensics. forensicartifacts/artifacts — Digital Forensics artifact repository. lazza/recuperabit. poorbillionaire/usn-journal-parser — Python script to parse the NTFS USN Journal. thewhiteninja/ntfstool — Forensics tool for NTFS (parser, mft, bitlocker, deleted files). williballenthin/python-ntfs — Open source Python library for NTFS analysis.