BigHugger
sk Skill · mukul975

analyzing-mft-for-deleted-file-recovery

Analyze the NTFS Master File Table ($MFT) with MFTECmd, analyzeMFT, and X-Ways Forensics to recover metadata and content of deleted files by examining MFT record entries, $LogFile, $UsnJrnl, and MFT slack space. Use when recovering evidence of deleted files, reconstructing NTFS file-system timelines, or detecting anti-forensic timestomping during a Windows forensic examination.

installs 8w
0
30-day movement
starts with the next reading
Related entries
1
Connections
0
powershelllogfileusn-journalpythonmftecmdfile-recoveryPythondfirdeleted-filesfile-system-forensicsmft-slack-spacentfsmft
Host repository
mukul975/Anthropic-Cybersecurity-Skills
Version
1.0
Licence
Apache-2.0
Host stars
33k
Host language
Python