HOW TO INVESTIGATE FILES WITH FTK IMAGER

Apr 17, 2014

by Mark Stam

 

The Master File Table or MFT can be considered one of the most important files in the NTFS file system, as it keeps records of all files in a volume, the physical location of the files on the drive and file metadata. One of the most important tasks of a computer forensics expert is making file artifacts and metadata visible.

What you will learn:

  • How to locate file artifacts and metadata within the Master File Table

  • How to recover file data with FTK Imager

What you should know:

  • Familiarity with the normal layout of a Windows File System

This article describes, in a straightforward manner, the process of extracting NTFS file system data from a physical device. NTFS uses the Master File Table (MFT) as a database to keep track of files. We can use the MFT to investigate data and find detailed information about files. In this example I use FTK Imager 3.1.4.6 to find a picture (JPEG file) in Windows 7.

STARTING FTK IMAGER

Open....

© HAKIN9 MEDIA SP. Z O.O. SP. K. 2023