INDXParse is a suite of tools forensic investigators can use to inspect NTFS artifacts. Although INDXParse was once a single" rel="nofollow" target="_blank">http://www.williballenthin.com/forensics/indx/">single tool for working with directory index entries, the project now includes many more capabilities. These includes file enumeration, metadata extraction, logical tree browser GUI, and more.
Be the first to review this listing!
© 2020 Copyright | DFIR Training