Skip to main content

AnalyzeMFT

AnalyzeMFT is a Python script designed to translate the NTFS Master File Table (MFT) into a human-readable and searchable format, such as CSV. This tool is useful for digital forensics, file system analysis, and understanding the structure of NTFS volumes.

Features

  • Parse NTFS MFT files
  • Generate CSV output of MFT records
  • Create timeline in CSV format
  • Produce bodyfile output for timeline analysis
  • Support for local timezone reporting
  • Anomaly detection (optional)
  • Debugging output (optional)

Requirements

  • Python 3.x

Installation

  1. Clone this repository or download the script files.
  2. Ensure you have Python 3.x installed on your system.

Basic usage:

python AnalyzeMFT.py -f <mft_file> -o <output_file>

Versioning

Current version: 2.1 Beta/Testing Version: 3.0

Author

Benjamin Cance (bjc@tdx.li)

License

Copyright Benjamin Cance 2024

Contributing

If you'd like to contribute to this project, please submit a pull request or open an issue on the project's repository.

Disclaimer

This tool is provided as-is, without any warranties. Use at your own risk and ensure you have the necessary permissions before analyzing any file systems or MFT data.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

analyzemft-2.1.1.tar.gz (10.6 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

analyzeMFT-2.1.1-py3-none-any.whl (12.9 kB view details)

Uploaded Python 3

File details

Details for the file analyzemft-2.1.1.tar.gz.

File metadata

  • Download URL: analyzemft-2.1.1.tar.gz
  • Upload date:
  • Size: 10.6 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/5.1.1 CPython/3.12.5

File hashes

Hashes for analyzemft-2.1.1.tar.gz
Algorithm Hash digest
SHA256 81e52553800224af2cfac4aca02fd550152b82e3bb046d2ebd7e53fe29c14594
MD5 410e1b701fb684bd648eefac01495ff0
BLAKE2b-256 379e9f3bbec2d8a7a4bb9083635e031ebc2979594c893e89e1760b300203289f

See more details on using hashes here.

File details

Details for the file analyzeMFT-2.1.1-py3-none-any.whl.

File metadata

  • Download URL: analyzeMFT-2.1.1-py3-none-any.whl
  • Upload date:
  • Size: 12.9 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/5.1.1 CPython/3.12.5

File hashes

Hashes for analyzeMFT-2.1.1-py3-none-any.whl
Algorithm Hash digest
SHA256 093571762e7a6b19cf3327ef64dcfe6f3d7be518e70d4329aaad7811cd87c19e
MD5 6c16f9323ee606857b10e2caea419847
BLAKE2b-256 a29a0d59ea4fc3d99c32a61a29bdd4fcc45cf657f2f403393e755f29fd05c026

See more details on using hashes here.

Release history Release notifications | RSS feed

3.1.1

2 files

3.0.6.7

2 files

3.0.6.6

2 files

3.0.6.3

2 files

3.0.6.2

2 files

3.0.6

2 files

3.0.5

2 files

3.0.2

2 files

3.0

2 files

2.1.1.2

2 files

This release

2.1.1 This release

2 files

2.1.0

2 files

2.0.19

1 file

2.0.18

1 file

2.0.17

1 file

2.0.16

1 file

2.0.15

1 file

2.0.14

1 file

2.0.13

1 file

2.0.12

1 file

2.0.10

1 file

2.0.9

1 file

2.0.8

1 file

2.0.6

1 file

2.0.5

1 file

2.0.4

1 file

2.0.3

1 file

2.0.0

1 file

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page