AnalyzeMFT
AnalyzeMFT is a Python script designed to translate the NTFS Master File Table (MFT) into a human-readable and searchable format, such as CSV. This tool is useful for digital forensics, file system analysis, and understanding the structure of NTFS volumes.
Features
- Parse NTFS MFT files
- Generate CSV output of MFT records
- Create timeline in CSV format
- Produce bodyfile output for timeline analysis
- Support for local timezone reporting
- Anomaly detection (optional)
- Debugging output (optional)
Requirements
- Python 3.x
Installation
- Clone this repository or download the script files.
- Ensure you have Python 3.x installed on your system.
Basic usage:
python AnalyzeMFT.py -f <mft_file> -o <output_file>
Versioning
Current version: 2.1 Beta/Testing Version: 3.0
Author
Benjamin Cance (bjc@tdx.li)
License
Copyright Benjamin Cance 2024
Contributing
If you'd like to contribute to this project, please submit a pull request or open an issue on the project's repository.
Disclaimer
This tool is provided as-is, without any warranties. Use at your own risk and ensure you have the necessary permissions before analyzing any file systems or MFT data.
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file analyzemft-2.1.1.2.tar.gz.
File metadata
- Download URL: analyzemft-2.1.1.2.tar.gz
- Upload date:
- Size: 12.0 kB
- Tags: Source
- Uploaded using Trusted Publishing? No
- Uploaded via:
twine/5.1.1 CPython/3.12.5
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
df07e011d6ecaa2e08132d557f53ecf1ea7c3998d175d61915f263ac85cdc2c3
|
|
| MD5 |
e7978ec0c0e0cf7ce8657ac3fb98fbe6
|
|
| BLAKE2b-256 |
0fbd365881ec3f37e2953c285632005410d96c2fb43d28b128724df9e85d9a47
|
File details
Details for the file analyzeMFT-2.1.1.2-py3-none-any.whl.
File metadata
- Download URL: analyzeMFT-2.1.1.2-py3-none-any.whl
- Upload date:
- Size: 15.1 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? No
- Uploaded via:
twine/5.1.1 CPython/3.12.5
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
67c2e3fae557a29399aa12ad503baed0e44ea798f4cbc1202bd100ec4eaa953e
|
|
| MD5 |
e4ee171cb6d72b4aa5db9f11033a602f
|
|
| BLAKE2b-256 |
7ba31f694fcc38abb8f863546e72924a1699fd1ccd6edf90cd08598945460b7e
|