Skip to main content

AnalyzeMFT

AnalyzeMFT is a Python script designed to translate the NTFS Master File Table (MFT) into a human-readable and searchable format, such as CSV. This tool is useful for digital forensics, file system analysis, and understanding the structure of NTFS volumes.

Features

  • Parse NTFS MFT files
  • Generate CSV output of MFT records
  • Create timeline in CSV format
  • Produce bodyfile output for timeline analysis
  • Support for local timezone reporting
  • Anomaly detection (optional)
  • Debugging output (optional)

Requirements

  • Python 3.x

Installation

  1. Clone this repository or download the script files.
  2. Ensure you have Python 3.x installed on your system.

Basic usage:

python AnalyzeMFT.py -f <mft_file> -o <output_file>

Versioning

Current version: 3.0

Author

Benjamin Cance (bjc@tdx.li)

License

Copyright Benjamin Cance 2024

Contributing

If you'd like to contribute to this project, please submit a pull request or open an issue on the project's repository.

Disclaimer

This tool is provided as-is, without any warranties. Use at your own risk and ensure you have the necessary permissions before analyzing any file systems or MFT data.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

analyzemft-3.0.tar.gz (8.2 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

analyzeMFT-3.0-py3-none-any.whl (10.9 kB view details)

Uploaded Python 3

File details

Details for the file analyzemft-3.0.tar.gz.

File metadata

  • Download URL: analyzemft-3.0.tar.gz
  • Upload date:
  • Size: 8.2 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/5.1.1 CPython/3.12.5

File hashes

Hashes for analyzemft-3.0.tar.gz
Algorithm Hash digest
SHA256 4825d75af7a60b787737a2ff474902731a995ec0a13e0fbf3e1406def724f653
MD5 5f40f5f86ef545eb16f6d0d0619881b4
BLAKE2b-256 4155988b027573b094d2aad871f6a00b0935f03d6e99c107e10798dec9ea14ee

See more details on using hashes here.

File details

Details for the file analyzeMFT-3.0-py3-none-any.whl.

File metadata

  • Download URL: analyzeMFT-3.0-py3-none-any.whl
  • Upload date:
  • Size: 10.9 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/5.1.1 CPython/3.12.5

File hashes

Hashes for analyzeMFT-3.0-py3-none-any.whl
Algorithm Hash digest
SHA256 02328715ba7aec4a28bfeff6d3b466d1ab134fbb8cb7c0f33fb3ed19962e1db3
MD5 cb947d5fd5f254ce9b0afcd7ff9310fb
BLAKE2b-256 ae78450bab24fbf2edadee0f2431dbae2acdbc82c7b3495fea117bf2559e4a7f

See more details on using hashes here.

Release history Release notifications | RSS feed

3.1.1

2 files

3.0.6.7

2 files

3.0.6.6

2 files

3.0.6.3

2 files

3.0.6.2

2 files

3.0.6

2 files

3.0.5

2 files

3.0.2

2 files

This release

3.0 This release

2 files

2.1.1.2

2 files

2.1.1

2 files

2.1.0

2 files

2.0.19

1 file

2.0.18

1 file

2.0.17

1 file

2.0.16

1 file

2.0.15

1 file

2.0.14

1 file

2.0.13

1 file

2.0.12

1 file

2.0.10

1 file

2.0.9

1 file

2.0.8

1 file

2.0.6

1 file

2.0.5

1 file

2.0.4

1 file

2.0.3

1 file

2.0.0

1 file

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page