I do not know about others but I have been doing a lot of a parsing of NTFS-related files, whether it is the MFT itself, or running $LogFile through BinText.I am sure that one of the things that would help with folks adopting tools like this, particularly those that may require Python or Perl being installed, is an explanation or examples of how the information can be useful to an examiner/analyst.