MFT

Introduction to MFT Forensics

There are two methods of opening our MFT file. One is utilising MFTExplorer, The second is to convert our MFT into a CSV file using MFTeCMD and then import it into TimeLine Explorer

MFT Tools

MFTECmd

MFTeCMD is a tool developed by Eric Zimmerman that specializes in parsing the Master File Table from NTFS file systems. It extracts detailed information stored in the MFT entries, presenting them in a more digestible and analyzable format

Now we have a csv file. We can use the Timeline Explorer.

Time Explorer

Timeline Explorer is a tool designed for viewing, filtering, and analysing timelines during digital forensic investigations. It is often used to review large sets of event logs, file system records, and other timestamped data extracted during a forensic analysis

You can open the time explorer now and use it to analyse MFT records by applying different filters

Last updated