Skip to main content

AnalyzeMFT

AnalyzeMFT is a Python script designed to translate the NTFS Master File Table (MFT) into a human-readable and searchable format, such as CSV. This tool is useful for digital forensics, file system analysis, and understanding the structure of NTFS volumes.

Features

  • Parse NTFS MFT files
  • Generate CSV output of MFT records
  • Create timeline in CSV format
  • Produce bodyfile output for timeline analysis
  • Support for local timezone reporting
  • Anomaly detection (optional)
  • Debugging output (optional)

Requirements

  • Python 3.x

Installation

  1. Clone this repository or download the script files.
  2. Ensure you have Python 3.x installed on your system.

Basic usage:

python AnalyzeMFT.py -f <mft_file> -o <output_file>

Versioning

Current version: 2.1 Beta/Testing Version: 3.0

Author

Benjamin Cance (bjc@tdx.li)

License

Copyright Benjamin Cance 2024

Contributing

If you'd like to contribute to this project, please submit a pull request or open an issue on the project's repository.

Disclaimer

This tool is provided as-is, without any warranties. Use at your own risk and ensure you have the necessary permissions before analyzing any file systems or MFT data.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

analyzemft-2.1.1.2.tar.gz (12.0 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

analyzeMFT-2.1.1.2-py3-none-any.whl (15.1 kB view details)

Uploaded Python 3

File details

Details for the file analyzemft-2.1.1.2.tar.gz.

File metadata

  • Download URL: analyzemft-2.1.1.2.tar.gz
  • Upload date:
  • Size: 12.0 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/5.1.1 CPython/3.12.5

File hashes

Hashes for analyzemft-2.1.1.2.tar.gz
Algorithm Hash digest
SHA256 df07e011d6ecaa2e08132d557f53ecf1ea7c3998d175d61915f263ac85cdc2c3
MD5 e7978ec0c0e0cf7ce8657ac3fb98fbe6
BLAKE2b-256 0fbd365881ec3f37e2953c285632005410d96c2fb43d28b128724df9e85d9a47

See more details on using hashes here.

File details

Details for the file analyzeMFT-2.1.1.2-py3-none-any.whl.

File metadata

  • Download URL: analyzeMFT-2.1.1.2-py3-none-any.whl
  • Upload date:
  • Size: 15.1 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/5.1.1 CPython/3.12.5

File hashes

Hashes for analyzeMFT-2.1.1.2-py3-none-any.whl
Algorithm Hash digest
SHA256 67c2e3fae557a29399aa12ad503baed0e44ea798f4cbc1202bd100ec4eaa953e
MD5 e4ee171cb6d72b4aa5db9f11033a602f
BLAKE2b-256 7ba31f694fcc38abb8f863546e72924a1699fd1ccd6edf90cd08598945460b7e

See more details on using hashes here.

Release history Release notifications | RSS feed

3.1.1

2 files

3.0.6.7

2 files

3.0.6.6

2 files

3.0.6.3

2 files

3.0.6.2

2 files

3.0.6

2 files

3.0.5

2 files

3.0.2

2 files

3.0

2 files

This release

2.1.1.2 This release

2 files

2.1.1

2 files

2.1.0

2 files

2.0.19

1 file

2.0.18

1 file

2.0.17

1 file

2.0.16

1 file

2.0.15

1 file

2.0.14

1 file

2.0.13

1 file

2.0.12

1 file

2.0.10

1 file

2.0.9

1 file

2.0.8

1 file

2.0.6

1 file

2.0.5

1 file

2.0.4

1 file

2.0.3

1 file

2.0.0

1 file

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page