Prepare and Open MFT Evidence¶
Start with a case question¶
Prepare before you search
Example: Does the preserved NTFS metadata contain a record for invoice-review.txt, what path and state does it show, and which independent source could clarify its change sequence?
- Protect the source
Retain the original acquisition or extracted$MFT. Analyse an identified working copy in a controlled case directory. - Verify integrity
Record the source path, volume or image identifier, byte size, acquisition time, hash, and matching working-copy hash. - Record the environment
Save the MFTExplorer executable path, displayed version, examiner, case time zone, workstation time, and relevant settings. - Keep companion sources
Preserve$UsnJrnl:$J,$LogFile,$Boot, directory indexes, and the disk image when available. The$MFTis one view of the activity.
Do not open the live system file as your default workflow
The live C:\$MFT is locked and the system continues to change. Use a forensic image or a properly acquired copy. If live collection is authorised and necessary, record the collection tool, command, time, errors, and effect on the source system.
Open the application¶
MFTExplorer is available in SUSA at:
Launch MFTExplorer.exe, then record the version shown in the title bar. The supplied screenshot shows the blank workspace before an evidence file is loaded.

Know the workspace¶
Open a preserved $MFT¶
- 1Confirm the working copyCompare its hash with the acquisition manifest and record the original volume or image.
- 2Use File > OpenSelect the identified `$MFT` working copy. Do not substitute a CSV or the live locked file.
- 3Wait for parsing to finishLarge MFTs can take time. Confirm the tree and record grid populate and record any warnings.
- 4Validate the root contextCheck expected NTFS metadata records and compare the volume context with `$Boot`, the image, or acquisition notes.
Stop if the evidence boundary is unclear
Do not compensate for a missing hash, uncertain volume, truncated file, or parse warning by searching harder. Resolve and record the source issue first.