MFT
There are two methods of opening our MFT file. One is utilising MFTExplorer, The second is to convert our MFT into a CSV file using MFTeCMD and then import it into TimeLine Explorer
MFT Tools
MFTECmd
MFTeCMD is a tool developed by Eric Zimmerman that specializes in parsing the Master File Table from NTFS file systems. It extracts detailed information stored in the MFT entries, presenting them in a more digestible and analyzable format
Now we have a csv file. We can use the Timeline Explorer.
Time Explorer
Timeline Explorer is a tool designed for viewing, filtering, and analysing timelines during digital forensic investigations. It is often used to review large sets of event logs, file system records, and other timestamped data extracted during a forensic analysis
You can open the time explorer now and use it to analyse MFT records by applying different filters

Last updated
