Skip to content

Prepare and Open MFT Evidence

Start with a case question

Prepare before you search

Example: Does the preserved NTFS metadata contain a record for invoice-review.txt, what path and state does it show, and which independent source could clarify its change sequence?

  • Protect the source
    Retain the original acquisition or extracted $MFT. Analyse an identified working copy in a controlled case directory.
  • Verify integrity
    Record the source path, volume or image identifier, byte size, acquisition time, hash, and matching working-copy hash.
  • Record the environment
    Save the MFTExplorer executable path, displayed version, examiner, case time zone, workstation time, and relevant settings.
  • Keep companion sources
    Preserve $UsnJrnl:$J, $LogFile, $Boot, directory indexes, and the disk image when available. The $MFT is one view of the activity.

Do not open the live system file as your default workflow

The live C:\$MFT is locked and the system continues to change. Use a forensic image or a properly acquired copy. If live collection is authorised and necessary, record the collection tool, command, time, errors, and effect on the source system.

Open the application

MFTExplorer is available in SUSA at:

C:\Tools\Zimmerman Tools\net9\MFTExplorer

Launch MFTExplorer.exe, then record the version shown in the title bar. The supplied screenshot shows the blank workspace before an evidence file is loaded.

MFTExplorer version 2.1.0 blank workspace showing the directory tree, result grid, properties, raw-byte pane, and Overview and Details tabs
Supplied MFTExplorer screenshot preserved as the interface reference. No records appear until a supported evidence file is opened.

Know the workspace

MFT ExplorerFile   Tools   Help
1 · Directory treeNavigate reconstructed parent and child paths.
2 · Record gridSearch, filter, sort, group, and select matching records.
3 · PropertiesReview allocation state, flags, directory state, ADS, and anomaly indicators.
4 · Raw recordRetain byte-level context when a parsed field needs validation.
5 · Overview / DetailsInspect attributes, timestamps, names, and data streams.

Open a preserved $MFT

  1. 1
    Confirm the working copyCompare its hash with the acquisition manifest and record the original volume or image.
  2. 2
    Use File > OpenSelect the identified `$MFT` working copy. Do not substitute a CSV or the live locked file.
  3. 3
    Wait for parsing to finishLarge MFTs can take time. Confirm the tree and record grid populate and record any warnings.
  4. 4
    Validate the root contextCheck expected NTFS metadata records and compare the volume context with `$Boot`, the image, or acquisition notes.

Stop if the evidence boundary is unclear

Do not compensate for a missing hash, uncertain volume, truncated file, or parse warning by searching harder. Resolve and record the source issue first.