MFT删文件分析
原名:analyzing-mft-for-deleted-file-recovery
使用MFTECmd或analyzeMFT分析NTFS主文件表($MFT),提取文件元数据、时间戳及记录信息,支持深度取证分析。
- 分类
- 开发提效
- 版本
- v1.0
- 作者
- 弈韬(@ra1nzzz)
- 下载
- 1
- 收藏
- 0
- 发布
- 2026-08-18
- 更新
- 2026-08-19
- TRACE 评分
- 3.4 / 5
内容概览
The NTFS Master File Table ($MFT) is the central metadata repository for every file and directory on an NTFS volume. Each file is represented by at least one 1024-byte MFT record containing attributes such as $STANDARD INFORMATION (timestamps, permissions), $FILE NAME (name, parent directory, timestamps), and $DATA (file content or cluster run pointers). When a file is deleted, its MFT record is marked as inactive (InUse flag cleared) but the metadata remains until the entry is reallocated by a new file. This persistence makes MFT analysis a primary technique for recovering deleted file evidence, reconstructing file system timelines, and detecting anti-forensic activity such as timestomping. - When investigating security incidents that require analyzing mft for deleted file recovery - When building detection rules or threat hunting queries for this domain - When SOC analysts need structu…