
Windows Forensic Series Part 11: Analyzing the Master File Table (MFT)
Threat IntelForensicWindowsNTFSMFTKAPEMFTECmdFile System Analysis
This is part 11 of a Windows forensic series focusing on analyzing the Master File Table (MFT) of the Windows NTFS file system. The article covers the extraction of $MFT using KAPE (Kroll Artifact Parser and Extractor), conversion to CSV format using MFTECmd, and searching for deleted files. The content provides technical guidance on forensic analysis techniques for Windows systems using these specific tools to examine file system metadata.