https://github.com/ColinFinck/ntfs Skip to content Toggle navigation Sign up * Product + Actions Automate any workflow + Packages Host and manage packages + Security Find and fix vulnerabilities + Codespaces Instant dev environments + Copilot Write better code with AI + Code review Manage code changes + Issues Plan and track work + Discussions Collaborate outside of code Explore + All features + Documentation + GitHub Skills + Blog * Solutions For + Enterprise + Teams + Startups + Education By Solution + CI/CD & Automation + DevOps + DevSecOps Resources + Learning Pathways + White papers, Ebooks, Webinars + Customer Stories + Partners * Open Source + GitHub Sponsors Fund open source developers + The ReadME Project GitHub community articles Repositories + Topics + Trending + Collections * Pricing Search or jump to... Search code, repositories, users, issues, pull requests... Search [ ] Clear Search syntax tips Provide feedback We read every piece of feedback, and take your input very seriously. [ ] [ ] Include my email address so I can be contacted Cancel Submit feedback Saved searches Use saved searches to filter your results more quickly Name [ ] Query [ ] To see all available qualifiers, see our documentation. Cancel Create saved search Sign in Sign up You signed in with another tab or window. Reload to refresh your session. You signed out in another tab or window. Reload to refresh your session. You switched accounts on another tab or window. Reload to refresh your session. Dismiss alert {{ message }} ColinFinck / ntfs Public * Notifications * Fork 23 * Star 355 An implementation of the NTFS filesystem in a Rust crate, usable from firmware level up to user-mode. License Apache-2.0, MIT licenses found Licenses found Apache-2.0 LICENSE-APACHE MIT LICENSE-MIT 355 stars 23 forks Activity Star Notifications * Code * Issues 0 * Pull requests 1 * Discussions * Actions * Security * Insights More * Code * Issues * Pull requests * Discussions * Actions * Security * Insights ColinFinck/ntfs This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository. master Switch branches/tags [ ] Branches Tags Could not load branches Nothing to show {{ refName }} default View all branches Could not load tags Nothing to show {{ refName }} default View all tags Name already in use A tag already exists with the provided branch name. Many Git commands accept both tag and branch names, so creating this branch may cause unexpected behavior. Are you sure you want to create this branch? Cancel Create 1 branch 5 tags Code * Local * Codespaces * Clone HTTPS GitHub CLI [https://github.com/C] Use Git or checkout with SVN using the web URL. [gh repo clone ColinF] Work fast with our official CLI. Learn more about the CLI. * Open with GitHub Desktop * Download ZIP Sign In Required Please sign in to use Codespaces. Launching GitHub Desktop If nothing happens, download GitHub Desktop and try again. Launching GitHub Desktop If nothing happens, download GitHub Desktop and try again. Launching Xcode If nothing happens, download Xcode and try again. Launching Visual Studio Code Your codespace will open once ready. There was a problem preparing your codespace, please try again. Latest commit @ColinFinck ColinFinck Merge pull request #30 from poliorcetics/binrw-update ... cf4c127 Oct 4, 2023 Merge pull request #30 from poliorcetics/binrw-update deps: update to binrw 0.12 cf4c127 Git stats * 149 commits Files Permalink Failed to load latest commit information. Type Name Latest commit message Commit time .github/workflows CI: Turn off --verbose, but print the Rust version instead. January 24, 2023 19:24 examples/ntfs-shell Implement suggested traits and use Display over Debug in ntfs-shell. June 13, 2023 07:00 img Fix a quirk in the logo. April 14, 2022 20:24 src Fix broken intra-doc link. June 13, 2023 07:44 testdata Fix sparse file / sparse Data Run handling. January 24, 2023 19:04 .gitignore Update .gitignore October 17, 2021 20:50 CHANGELOG.md Bump version to 0.4.0 and add changes to CHANGELOG.md June 13, 2023 07:52 Cargo.toml deps: update to binrw 0.12 October 3, 2023 08:47 LICENSE-APACHE Relicense everything as MIT OR Apache-2.0 to enable a broader usage. December 15, 2021 20:46 LICENSE-MIT Relicense everything as MIT OR Apache-2.0 to enable a broader usage. December 15, 2021 20:46 README.md Fix some typos. January 13, 2022 19:27 View code ntfs Rust crate ntfs-shell Library Features Not yet supported Examples License Further Resources README.md [ntfs] ntfs Rust crate crates.io docs.rs license: MIT OR Apache-2.0 by Colin Finck A low-level NTFS filesystem library implemented in Rust. NTFS is the primary filesystem in all versions of Windows (since Windows NT 3.1 in 1993). This crate is geared towards the NTFS 3.x versions used in Windows 2000 up to the current Windows 11. However, the basics are expected to be compatible to even earlier versions. The crate is no_std-compatible and therefore usable from firmware-level code up to user-mode applications. ntfs-shell ntfs-shell demo The ntfs-shell example comes with this crate to demonstrate all library features. Use it to explore the internal structures of an NTFS filesystem at any detail level, even of your running Windows partition. No artificial security restrictions will block you from accessing files and folders, extracting their data or Alternate Data Streams. The filesystem is opened read-only, so you can safely browse even a mounted filesystem without worrying about data corruption. That is also helpful to get an idea of the Windows NTFS driver, e.g. to find out when its lazy writer actually updates the data on disk. I originally wrote ntfs-shell for myself to comfortably develop the library in user-mode before running the code in production in kernel-mode. To build ntfs-shell, just clone this repo and call cargo build --example ntfs-shell --all-features To run it, pass the path to an NTFS image (on all operating systems) or to a partition (like \\.\C:, on Windows only with administrative privileges) to the resulting ntfs-shell binary. Calling help gives you a list of all supported commands. help COMMAND details the syntax of that command. Most commands that take a filename also take an NTFS File Record Number (if prepended by /). This File Record Number may be decimal or hexadecimal (if prepended by 0x). Some examples: fileinfo Windows fileinfo /146810 fileinfo /0x23d7a Library Features * For the impatient: Convenience functions to treat NTFS like any other filesystem and just read files and directories using Read/ Seek traits. At your option, you may also explore the filesystem at any detail level. * Reading arbitrary resident and non-resident attributes, attributes in Attribute Lists, and attributes connected over multiple Attribute List entries, including sparse attribute data. All of this together enables reading file data and Alternate Data Streams of any size and on-disk structure. * Iterating over a flattened "data-centric" view of the NTFS Attributes, abstracting away any nested Attribute List. * Efficiently finding files in a directory, adhering to the filesystem's $Upcase Table for case-insensitive search. * In-order iteration of directory contents at O(1). * Leveraging Rust's typesystem to handle the various types of NTFS indexes in a typesafe way. * Error propagation through a custom NtfsError type that implements Display. Where it makes sense, variants have additional fields to pinpoint any error to a specific location. * Full functionality even in a no_std environment with alloc. * No usage of unsafe anywhere. Checked arithmetic where needed. * Platform and endian independence. Not yet supported * Any write support * Caching for better performance * Compression * Encryption * Journaling * Quotas * Reparse Points * Security Descriptors Examples The following example dumps the names of all files and folders in the root directory of a given NTFS filesystem. The list is directly taken from the NTFS index, hence it's sorted in ascending order with respect to NTFS's understanding of case-insensitive string comparison. let mut ntfs = Ntfs::new(&mut fs).unwrap(); let root_dir = ntfs.root_directory(&mut fs).unwrap(); let index = root_dir.directory_index(&mut fs).unwrap(); let mut iter = index.entries(); while let Some(entry) = iter.next(&mut fs) { let entry = entry.unwrap(); let file_name = entry.key().unwrap(); println!("{}", file_name.name()); } Check out the docs, the tests, and the supplied ntfs-shell application for more examples on how to use the ntfs library. License This crate is licensed under either of * Apache License, Version 2.0 * MIT license at your option. Unless you explicitly state otherwise, any contribution intentionally submitted for inclusion in the work by you, as defined in the Apache-2.0 license, shall be dual licensed as above, without any additional terms or conditions. Further Resources * flatcap.github.io linux-ntfs documentation * ntfs-3g driver About An implementation of the NTFS filesystem in a Rust crate, usable from firmware level up to user-mode. Topics windows rust ntfs no-std Resources Readme License Apache-2.0, MIT licenses found Licenses found Apache-2.0 LICENSE-APACHE MIT LICENSE-MIT Activity Stars 355 stars Watchers 9 watching Forks 23 forks Report repository Releases 5 tags Contributors 4 * @ColinFinck ColinFinck Colin Finck * @poliorcetics poliorcetics Poliorcetics * @leofidus leofidus * @losynix losynix losynix Languages * Rust 100.0% Footer (c) 2023 GitHub, Inc. Footer navigation * Terms * Privacy * Security * Status * Docs * Contact GitHub * Pricing * API * Training * Blog * About You can't perform that action at this time.