dissect.ntfs
A Dissect module implementing a parser for the NTFS file system, used by the Windows operating system
Decision gist · record as of 2026-08-14
Yes, if you need to parse NTFS file systems programmatically for forensics, security analysis, or incident response. The package is actively maintained, has low install friction, and is part of a mature framework. The AGPL-3.0-or-later license is a consideration for proprietary projects but is standard for open-source security tools. No known vulnerabilities.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Python 3.10 or later; intended for use with NTFS file system images or volumes.
- Low friction installation as a pure-Python wheel with only two lightweight Dissect framework dependencies (dissect.cstruct and dissect.util).
- Actively maintained with recent commits and stable production status.
License · maintenance · safety
AGPL-3.0-or-later (agpl) — Licensed under AGPL-3.0-or-later, which requires that any modifications or derivative works using this package must also be released under AGPL-3.0 or a compatible later version. This is a strong copyleft license suitable for open-source projects but may restrict commercial or proprietary use.
last release 2026-02-24 (171 days) · last repo commit 2026-03-27 · 10 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 86,058 downloads/mo, #13,888 on PyPI
Alternatives
Verify before relying
pip install dissect.ntfs
from dissect.ntfs import NTFS
with open('/path/to/ntfs/image', 'rb') as f:
ntfs = NTFS(f)
# Access NTFS structures and data- Specific NTFS features or versions supported (e.g., NTFS 3.1, compression, encryption handling)
- Performance characteristics when parsing large or fragmented NTFS volumes
- Compatibility with NTFS variants (exFAT, ReFS) or edge cases
What it is and what it does
dissect.ntfs is a parser module for the NTFS file system, part of the larger Dissect framework for digital forensics and incident response. It provides programmatic access to NTFS structures, allowing developers to read and analyze Windows file systems at the binary level. The module is built on top of dissect.cstruct for binary data parsing and dissect.util for utility functions, keeping dependencies minimal and focused.
Typical use cases include forensic analysis of Windows systems, automated extraction of file metadata and content from NTFS volumes, and integration into larger investigation workflows. The module is designed for developers and information security professionals who need to parse NTFS data programmatically rather than through standard OS file access.
Use it for
- Forensic analysis of Windows disk images or NTFS volumes in incident response investigations
- Automated extraction of file metadata, timestamps, and content from NTFS file systems
- Integration into security tools and frameworks that need to analyze Windows storage structures
- Recovery or analysis of deleted files and unallocated space in NTFS volumes
- Parsing NTFS structures in cross-platform or headless environments without Windows OS
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes, if you need to parse NTFS file systems programmatically for forensics, security analysis, or incident response.
The package is actively maintained, has low install friction, and is part of a mature framework. The AGPL-3.0-or-later license is a consideration for proprietary projects but is standard for open-source security tools. No known vulnerabilities.
Install
dissect-ntfs on PyPI
Before you install
Low friction installation as a pure-Python wheel with only two lightweight Dissect framework dependencies (dissect.cstruct and dissect.util). Actively maintained with recent commits and stable production status.
Requires Python 3.10 or later; intended for use with NTFS file system images or volumes.
License in practice
Licensed under AGPL-3.0-or-later, which requires that any modifications or derivative works using this package must also be released under AGPL-3.0 or a compatible later version. This is a strong copyleft license suitable for open-source projects but may restrict commercial or proprietary use.
Quickstart
pip install dissect.ntfs
from dissect.ntfs import NTFS
with open('/path/to/ntfs/image', 'rb') as f:
ntfs = NTFS(f)
# Access NTFS structures and data
Verify before relying
- Specific NTFS features or versions supported (e.g., NTFS 3.1, compression, encryption handling)
- Performance characteristics when parsing large or fragmented NTFS volumes
- Compatibility with NTFS variants (exFAT, ReFS) or edge cases
Package facts
| License | AGPL-3.0-or-later agpl |
| Python support | Supports the current Python release >=3.10 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 2 packagesdissect.cstructdissect.util |
| Maintenance | Actively maintained 171 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 86,058 / month, #13,888 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 5 - Production/StableEnvironment :: ConsoleIntended Audience :: DevelopersIntended Audience :: Information TechnologyOperating System :: OS IndependentProgramming Language :: Python :: 3Topic :: Internet :: Log AnalysisTopic :: Scientific/Engineering :: Information AnalysisTopic :: SecurityTopic :: Utilities |
Evidence: dissect_ntfs-3.16-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “ntfs file system parser”
- dissect.ntfsParses and reads NTFS file systems, the primary file system used by…
- python-hostsManages hosts file entries programmatically—add, remove, import, and…
- dissect.hypervisorParses hypervisor disk, backup, and configuration files from various…
Give your agent the search over MCP, or paste the wish link into any chat.
More Utilities packages
Converts domain names between Unicode and ASCII-compatible encoding (Punycode) according to IDNA 2008 and Unicode Technical Standard 46, with security validation and broader script coverage than the standard library.
Install it if you work with internationalized domain names, need to validate domains, or use HTTP clients that depend on it transitively.
Detects and normalizes text encoding from unknown or ambiguous sources, supporting all IANA character sets that Python's core library provides codecs for, with the ability to register custom codecs.
Setuptools is a Python build backend and package management tool that handles building, distributing, and installing Python packages, including support for C/C++ extension modules.
Pluggy provides a plugin system that lets you define hook specifications and register implementations to be called in sequence, enabling extensible Python applications without tight coupling.
Install it if you're building an extensible application or framework.
Pygments is a syntax highlighter that colorizes source code and text in over 500 languages and formats, outputting to HTML, LaTeX, RTF, SVG, images, or ANSI terminal sequences.
Install it if you need to display or transform source code.
Six provides utility functions to write Python code that runs on both Python 2.7 and Python 3.3+, smoothing over language differences between the two versions.
See also dissect.cstruct · dissect.hypervisor · dissect.volume · acquire · dissect.util · dissect.target · olefile · mail-parser · minidump · ipsw-parser