LogoClawIndex
CasesSkillsAbout
LogoClawIndex

ClawIndex

OpenClaw Skills & Use Case Index

ClawIndex is an ecosystem-driven index of OpenClaw skills and real-world use cases.

Index

Skills·
Cases

Meta

About·
Disclaimer·
Email·
GitHub
© 2026 ClawIndex All Rights Reserved.

cybersec-analyzing-slack-space-and-file-system-artifacts - Analyze NTFS slack space and forensic artifacts

Examines NTFS slack space, MFT entries, the USN journal, and alternate data streams to recover hidden data and reconstruct file activity.

Tags

Updated: 2026-09-29

Capabilities

Typical Inputs

Typical Outputs

What this skill does

  • Extract NTFS system artifacts
  • Parse MFT entries
  • Analyze slack space
  • Parse USN journal records
  • Detect alternate data streams
  • Carve embedded files

Inputs

  • NTFS forensic disk image
  • Partition offset
  • Case output directories
  • Slack-space search patterns

Outputs

  • Extracted MFT file
  • Extracted USN journal
  • Extracted transaction log
  • Raw slack-space image
  • MFT analysis CSV
  • USN journal CSV
  • Carved embedded files
  • Slack-space search results

Requirements

  • NTFS forensic disk image
  • The Sleuth Kit tools
  • MFTECmd
  • MFTExplorer
  • Python
  • analyzeMFT or mft library
  • pyusn library
  • foremost
  • bulk_extractor

Source

  • Spec: SKILL.md
cybersecurity
digital forensics
NTFS
slack space
MFT
USN journal
alternate data streams
Extract NTFS system artifacts
Parse MFT entries
Analyze slack space
Parse USN journal records
NTFS forensic disk image
Partition offset
Case output directories
Extracted MFT file
Extracted USN journal
Extracted transaction log