1) Extract MFT using icat
2) parse using MFTAnalyzer
analyzeMFT.py -f mft.raw -o mftanalyzed.csv
ref: https://www.andreafortuna.org/2017/07/18/how-to-extract-data-and-timeline-from-master-file-table-on-ntfs-filesystem/
notes: can use https://github.com/jschicht/Mft2Csv/wiki/Mft2Csv to parse from live system
2) parse using MFTAnalyzer
analyzeMFT.py -f mft.raw -o mftanalyzed.csv
ref: https://www.andreafortuna.org/2017/07/18/how-to-extract-data-and-timeline-from-master-file-table-on-ntfs-filesystem/
notes: can use https://github.com/jschicht/Mft2Csv/wiki/Mft2Csv to parse from live system
No comments:
Post a Comment
Terima kasih