analyzing-slack-space-and-file-system-artifacts
mukul975/Anthropic-Cybersecurity-Skills
Workflow for analyzing NTFS slack space, MFT entries, the USN change journal, and alternate data streams to recover hidden data and reconstruct file activity, using Sleuth Kit tools, MFTECmd, and Python parsing scripts in forensic investigations.