Is there a tool for...
 
Notifications
Clear all

Is there a tool for finding MAC times in $MFT

5 Posts
3 Users
0 Reactions
838 Views
(@stamitz)
Eminent Member
Joined: 18 years ago
Posts: 34
Topic starter  

I'm looking for a tool to parse the $MFT file. I want to find all entries and also the according times. Sure, I've got the big tool which name starts with an E. (v6.8) and I know this tool is capable of finding all MFT entries. But, I'm looking for a tool like a perl script or something like that (I prefer open source tools -). If possible, I want to copy the file $MFT from an evidence file (with FTK Imager for example) and parse it.

Thanks !

Stamitz


   
Quote
(@bithead)
Noble Member
Joined: 20 years ago
Posts: 1206
 
Perl? Who ya gonna call? Harlan Carvey

Sung to the melody of the Ghostbusters Theme.

Windows Forensic Analysis & DVD Toolkit - ISBN-13 978-1-59749-156-3
Perl Scripting for Windows Security - ISBN-13 978-1-59749-173-0

Pretty sure there was something on the MFT in the first book, not far enough through the second to say for sure if that is covered.


   
ReplyQuote
Jamie
(@jamie)
Moderator
Joined: 5 years ago
Posts: 1288
 

Hi Stamitz,

Runtime Software's DiskExplorer for NTFS might provide a useful view on the $MFT file but I'm not sure if you can just import it by itself, you probably need to import an entire image (there's a free trial on their site.) It's not open source, though.

BTW, thanks for the banner link on your blog, much appreciated. Have you added the blog to the links section here?

Jamie


   
ReplyQuote
(@bithead)
Noble Member
Joined: 20 years ago
Posts: 1206
 

Almost forgot about this EnScript by Lance Mueller. Also, might check on the ability of Sleuth Kit Informer to parse the MFT.

Jamie, DiskExplorer can open a physical or logical drive or an image or virtual image or a remote physical drive.


   
ReplyQuote
(@stamitz)
Eminent Member
Joined: 18 years ago
Posts: 34
Topic starter  

Thanks for the advice Jamie ! I have just added a link to my techblog -)

DiskExplorer seems very complete but then again, no open source (and I already have WinHex, FTK, Encase etc.). I will have a look at Sleuthkit Informer and will mail a PM to keydet89 to ask about the power of perl.

Thanks BitHead !


   
ReplyQuote
Share: