MFT and USN parser that allows direct extraction in filesystem timeline format (mactime), dump all resident files in the MFT in their original folder structure and run yara rules over them all.
-
Updated
May 10, 2023 - Python
MFT and USN parser that allows direct extraction in filesystem timeline format (mactime), dump all resident files in the MFT in their original folder structure and run yara rules over them all.
A syntactic sugar PS module for managing NTFS Alternate Data Streams
Add a description, image, and links to the ntfs-ads topic page so that developers can more easily learn about it.
To associate your repository with the ntfs-ads topic, visit your repo's landing page and select "manage topics."