dfir_ntfs: an NTFS/FAT parser for digital forensics & incident response (Python 3 only.)
All timestamps reported by the tools are in UTC. (For FAT file systems, all timestamps are local or UTC, returned as is.)
The MACE notation is used:
In the WSL set of timestamps (and FAT):
This project is made available under the terms of the GNU GPL, version 3. See the 'License' file.
The first exception is the "nist-hacking-case.mft" file. This file is from the NIST Hacking Case, which is distributed by NIST. See the 'Use of NIST Information' section here: https://www.nist.gov/disclaimer.
The second exception is boot code embedded in some test data. This code is not covered by the GNU GPL, version 3.
(All exceptions are in the "test_data" directory, which is not installed.)
(c) Maxim Suhanov