Pranat Dayal Digital forensics and incident response scripts
Collects various system artifacts from a windows computer for the purpose of Digital Forensics and Incident response
Parses through a CSV dump of $MFT and prints out:
- Filename
- Filepath
- Timestamps
It also dumps $DATA from a particular file and can identify timestomping instances