analyzing-mft-for-deleted-file-recovery - NTFS MFT Deleted File Recovery
Analyze NTFS MFT to recover deleted file metadata and content
Tags
Updated: 2026-06-30Capabilities
Typical Inputs
Typical Outputs
What this skill does
- Parse MFT records
- Identify deleted file records
- Extract USN journal entries
- Parse $LogFile transactions
- Extract MFT slack space
- Compare $SI and $FN timestamps
- Cross-reference MFT with artifacts
Inputs
- Forensic disk image
- $MFT file
- $UsnJrnl file
- $LogFile file
- $Recycle.Bin folder
- Volume shadow copies
Outputs
- Deleted file metadata
- MFT analysis CSV
- USN journal CSV
- Timeline data
- Slack space findings
- Timestomping detection
Requirements
- MFTECmd or analyzeMFT
- FTK Imager or Arsenal Image Mounter
- Python 3.8+
- Timeline Explorer or Excel
