MultiDrive – free backup, clone & wipe disk utility from Atola Technology

All times are UTC - 5 hours [ DST ]




Post new topic Reply to topic  [ 12 posts ] 
Author Message
 Post subject: NTFS MFT analysis
PostPosted: August 1st, 2009, 2:29 
Offline

Joined: July 15th, 2008, 1:50
Posts: 95
I have a forensic investigation case.
An employer is seeking to analyse one of this employee's hard disk . A importanat file is deleted from 40GB NTFS partition and no software has shown any traces of the said file.
How to interpreat / analyse MFT records to reach upto a single 143KB excel file?
File system guru's please give hints & advice.


Top
 Profile  
 
 Post subject: Re: NTFS MFT analysis
PostPosted: August 1st, 2009, 3:49 
Offline

Joined: March 22nd, 2009, 0:19
Posts: 269
Location: behind the platter
It all depends on how it was deleted, when and where and so on... It may give you a clue on MFT and it may give you a clue on unallocated space or in the slack space. Where are you located???

Hope you are working on this case from a cloned drive...


Top
 Profile  
 
 Post subject: Re: NTFS MFT analysis
PostPosted: August 1st, 2009, 9:36 
Offline

Joined: July 18th, 2006, 3:05
Posts: 7476
Location: ITALY
Hope no one of the parts involved is reading this forum...


Top
 Profile  
 
 Post subject: Re: NTFS MFT analysis
PostPosted: August 2nd, 2009, 10:57 
Offline

Joined: July 15th, 2008, 1:50
Posts: 95
disk is forensically captured using standard procedure. BlackSt i did not understand what do you mean.
all i know that mft's & its mirror copies alongwith log files we often recover hold the key secrets to data link & most pro's can decode mfts manually to trace sectors where file fragments are located.
instead of using ready to use tools which every tom dick & harry use , this will be more precise method.


Top
 Profile  
 
 Post subject: Re: NTFS MFT analysis
PostPosted: August 2nd, 2009, 13:38 
Offline

Joined: July 18th, 2006, 3:05
Posts: 7476
Location: ITALY
I mean that :

learner wrote:
I have a forensic investigation case.
An employer is seeking to analyse one of this employee's hard disk . A importanat file is deleted from 40GB NTFS partition and no software has shown any traces of the said file.
How to interpreat / analyse MFT records to reach upto a single 143KB excel file?
File system guru's please give hints & advice.


... some information should be strictly confidential (I would have been MORE AND MORE GENERIC in public) and discussed maybe in PM.
Only this. 8)


Top
 Profile  
 
 Post subject: Re: NTFS MFT analysis
PostPosted: August 2nd, 2009, 13:40 
Offline
User avatar

Joined: August 15th, 2006, 3:01
Posts: 3522
Location: CDRLabs @ Chandigarh [ India ]
Bl ,
Lol Hee Hee ,How Always Think Miles ahead .

_________________
Regards
Amarbir S Dhillon , Chandigarh Data Recovery Labs [India]
Logical,Semi Physical And Physical Data Recovery
Website-> http://www.chandigarhdatarecovery.com


Top
 Profile  
 
 Post subject: Re: NTFS MFT analysis
PostPosted: August 2nd, 2009, 14:00 
Offline

Joined: July 18th, 2006, 3:05
Posts: 7476
Location: ITALY
Eh, Amarbir, my friend.... probably more experience 8). All the best.


Top
 Profile  
 
 Post subject: Re: NTFS MFT analysis
PostPosted: August 2nd, 2009, 17:14 
Offline
User avatar

Joined: May 6th, 2009, 5:28
Posts: 116
Location: Somewhere near UK
Hi Learner,
you want to learn what happens with MFT? - start with simple process.
Create new NTFS installation - same as case on hand.

Scan the drive for MFT entries - you can get text output of MFT entries.
Copy one new excel file to the drive.

Scan drive for all MFT entries - observe the one for your Excel file - hurray :D
Delete the Excel file - scan the drive for MFT entries - observe MFT entry of your file.
Remove the file from Recycle - scan the drive for MFT entries - observe MFT entry for your file.


Top
 Profile  
 
 Post subject: Re: NTFS MFT analysis
PostPosted: August 2nd, 2009, 23:41 
Offline

Joined: July 15th, 2008, 1:50
Posts: 95
thanks derp. yes to begin with this is best suggestion .now question is how to open mft's for this analysis. Cam we open it in wordpad or something? also there is backup file of main mft. can you tell name of the files needs to be analysed & if it is corrupt/traped in bad sectors, where is its back up?
Furthermore , if you find that entry how to actually go to that sector & recreate that file from its fragments /sectors?
Thanks


Top
 Profile  
 
 Post subject: Re: NTFS MFT analysis
PostPosted: August 2nd, 2009, 23:54 
Offline

Joined: August 31st, 2006, 17:53
Posts: 354
Location: Birmingham, Al
What forensics tools do you have?
What sector examining tools do you have?


Top
 Profile  
 
 Post subject: Re: NTFS MFT analysis
PostPosted: August 3rd, 2009, 12:18 
Offline

Joined: July 15th, 2008, 1:50
Posts: 95
Steve wrote:
What forensics tools do you have?
What sector examining tools do you have?


We use hardware duplicators like ninja /salvationdata /mediatools pro/ FTK imager etc. For analaysis we have winhex , we are very new in that & thats the reason to give a request.


Top
 Profile  
 
 Post subject: Re: NTFS MFT analysis
PostPosted: August 3rd, 2009, 14:20 
Offline

Joined: August 31st, 2006, 17:53
Posts: 354
Location: Birmingham, Al
learner wrote:
Steve wrote:
What forensics tools do you have?
What sector examining tools do you have?


We use hardware duplicators like ninja /salvationdata /mediatools pro/ FTK imager etc. For analaysis we have winhex , we are very new in that & thats the reason to give a request.


Grab a trial version of Runtimes NTFS explorer, then you can view
MFT's ,and INDX's for file remants. if it helps then you can purchase
it. RStudio allows you to look for file types.
You might also look into FTK full version, or Encase.


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 12 posts ] 

All times are UTC - 5 hours [ DST ]


Who is online

Users browsing this forum: Google [Bot] and 61 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group