{"repo":"sumeshi/mft2es","free":true,"listed":false,"github":"https://github.com/sumeshi/mft2es","clone":"git clone https://github.com/sumeshi/mft2es.git","description":"A command-line tool for parsing Windows Master File Table ($MFT) and importing the results into Elasticsearch.","language":"Python","stars":12,"topics":["python","elasticsearch","mft","windows","parser","dfir","forensics","forensics-tools"],"license":"MIT","category":"cli-tools","readme_excerpt":"mft2es A command-line tool and Python library for parsing Windows Master File Table ( $MFT ) and importing the results into Elasticsearch. mft2es leverages the Rust-based parser pymft-rs, making it faster than pure-Python parsers in many cases. Usage mft2es can be used as a standalone command-line tool or integrated directly into your Python scripts. Arguments mft2es can process multiple files at once: mft2es can recursively process all MFT and $MFT files under a specified directory: Options Examples When using from the command line: When using from a Python script: With credentials for Elastic Security: With timeline analysis mode: With tags for host identification: [!WARNING] TLS certificate verification is enabled by default for Elasticsearch connections. Use --no-verify-certs only when connecting to a trusted cluster with self-signed or otherwise unverifiable certificates. Appendix mft2json mft2es also includes mft2json , a command-line tool for converting Windows Master File Table records into JSON files. :sushi: :sushi: :sushi: With tags for host identification: You can also convert $MFT records directly into a Python List[dict] object: Timeline Analysis mft2es supports timeline analysis mode that creates MACB (Modified, Accessed, Changed, Birth) timeline records for forensic investigation. Output Format Examples Standard Mode Timeline Mode Installation From PyPI With uv From GitHub Releases Standalone binaries built with Nuitka are available from GitHub Releases for sy","default_branch":null,"files":null,"tree":[],"storefront":"/r/sumeshi","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/sumeshi/mft2es/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}