{"categories":[{"label":"Utilities","url":"https://skillfed.io/packages/category/utilities/11"},{"label":"Security","url":"https://skillfed.io/packages/category/security/3"},{"label":"Information Analysis","url":"https://skillfed.io/packages/category/scientific-engineering-information-analysis/3"},{"label":"Log Analysis","url":"https://skillfed.io/packages/category/internet-log-analysis"}],"enrichment":{"capability":"Parses and reads NTFS file systems, the primary file system used by Windows operating systems, enabling programmatic access to NTFS structures and data.","skillfed_tags":["forensics","ntfs-parser","incident-response"],"use_cases":["Forensic analysis of Windows disk images or NTFS volumes in incident response investigations","Automated extraction of file metadata, timestamps, and content from NTFS file systems","Integration into security tools and frameworks that need to analyze Windows storage structures","Recovery or analysis of deleted files and unallocated space in NTFS volumes","Parsing NTFS structures in cross-platform or headless environments without Windows OS"],"what_it_does":"dissect.ntfs is a parser module for the NTFS file system, part of the larger Dissect framework for digital forensics and incident response. It provides programmatic access to NTFS structures, allowing developers to read and analyze Windows file systems at the binary level. The module is built on top of dissect.cstruct for binary data parsing and dissect.util for utility functions, keeping dependencies minimal and focused.\n\nTypical use cases include forensic analysis of Windows systems, automated extraction of file metadata and content from NTFS volumes, and integration into larger investigation workflows. The module is designed for developers and information security professionals who need to parse NTFS data programmatically rather than through standard OS file access.","worth_installing":"Yes, if you need to parse NTFS file systems programmatically for forensics, security analysis, or incident response. The package is actively maintained, has low install friction, and is part of a mature framework. The AGPL-3.0-or-later license is a consideration for proprietary projects but is standard for open-source security tools. No known vulnerabilities."},"id":"dissect-ntfs","links":{"html":"https://skillfed.io/packages/dissect-ntfs","md":"https://skillfed.io/packages/dissect-ntfs.md","pypi":"https://pypi.org/project/dissect-ntfs/"},"maintenance":{"status":"active"},"meta":{"latest_release":"2026-02-24","license_spdx":"AGPL-3.0-or-later","license_treatment":"agpl","name":"dissect.ntfs","python_support":"supports_current","summary":"A Dissect module implementing a parser for the NTFS file system, used by the Windows operating system"},"popularity":{"monthly_downloads":86058,"position":13888,"tier":"top_15000"},"security":{"n_vulnerabilities":0},"version":"3.16"}
