phantom-trace-ntfs
PulseGate's liveness check found it on 3 Oct 2026; it is registered on GitHub and PyPI and has been in the index since 3 Oct 2026. How this is checked
phantom-trace-ntfs is a read-only command-line tool that checks consistency across NTFS structures, including the MFT, bitmaps, and run lists. It is intended for digital forensics, incident response, and blue-team investigations of disk images.
Inferred · not functionally tested
Overview
6 featuresPurpose: Detecting inconsistencies between NTFS metadata structures during digital forensic investigations.
Inferred · not functionally tested
Audience: digital forensics and incident response professionals
Inferred · not functionally tested
Functions: Unknown
Interfaces: API: unknown · MCP: unknown · CLI: indicated (inferred, not tested) · Self-hosting: indicated (inferred, not tested)
Recorded constraints: pricing: open_source · license: MIT · platforms: CLI · deployment: cli, self_hosted
Constraint provenance is unknown; confirm requirements with the publisher.
Record sources: pypi.org · github.com. These links do not verify the individual claims.
In the Malware analysis & digital forensics space, phantom-trace-ntfs takes a focused approach. Inferred · not functionally tested: It focuses on detecting inconsistencies between NTFS metadata structures during digital forensic investigations. Inferred · not functionally tested: phantom-trace-ntfs is an open-source project aimed at digital forensics and incident response professionals. Basis unknown · not verified: The project is open source (MIT). Basis unknown · not verified: It runs on the command line, and it can be self-hosted.
It is developed by JackSessions, and it first shipped in 2026. Development happens publicly on GitHub with 13 commits in the last 90 days. Inferred · not functionally tested: Key capabilities include MFT checking, bitmap checking, and run-list checking.
Summary written by a language model from the project’s public pages.
Tasks: Inferred · not functionally tested
- MFT checking
- Bitmap checking
- Run-list checking
- Read-only analysis
- Disk-image analysis
- Timestomp detection
Topics: Inferred · not functionally tested
Built with & integrations
- Claude Code
- commit fd3063250891 · since Oct 2026
Trust & compliance
Indexing history
1What PulseGate has recorded for this listing
- Indexed3 Oct · 13:57 UTCphantom-trace-ntfs seen via PyPI Bulk EnumeratorSource: PyPI Bulk Enumerator · Open
Frequently asked questions about phantom-trace-ntfs
- What does phantom-trace-ntfs do?
- Inferred · not functionally tested: Phantom-trace-ntfs focuses on detecting inconsistencies between NTFS metadata structures during digital forensic investigations. It is catalogued under Malware analysis & digital forensics on PulseGate.
- Who is phantom-trace-ntfs for?
- Inferred · not functionally tested: phantom-trace-ntfs is an open-source project built for digital forensics and incident response professionals.
- Is phantom-trace-ntfs free?
- Basis unknown · not verified: Yes — phantom-trace-ntfs is open source under the MIT license and free to use.
- What platforms does phantom-trace-ntfs run on?
- Basis unknown · not verified: phantom-trace-ntfs runs on the command line. It can also be self-hosted.
- Is phantom-trace-ntfs still maintained?
- PulseGate's liveness check found it on 3 Oct 2026. Its GitHub repository shows 13 commits in the last 90 days.
- What are alternatives to phantom-trace-ntfs?
- Similar projects tracked by PulseGate include Hindsight Foundry, torikago, and runtime-trace.Hindsight Foundrytorikagoruntime-trace
- Who develops phantom-trace-ntfs?
- phantom-trace-ntfs is developed by JackSessions.
- How long has phantom-trace-ntfs been around?
- phantom-trace-ntfs first shipped in 2026.
Also in Malware analysis & digital forensics
Same category — not a similarity match