Анализ MFT NTFS для восстановления удалённых файлов
★ 8.4 · security
analyzing-mft-for-deleted-file-recovery is a Claude Code skill that analyzes the NTFS Master File Table ($MFT) to recover metadata and content of deleted files using MFTECmd, analyzeMFT, and X-Ways Forensics. It examines 1024-byte MFT record attributes — $STANDARD_INFORMATION, $FILE_NAME, and $DATA — alongside $LogFile transactions, USN Journal ($UsnJrnl:$J) entries, and MFT slack space to surface evidence that survives after deletion. Supported disk image formats include E01, raw/dd, VMDK, and VHDX, with CSV output processed in Timeline Explorer or Excel. Designed for DFIR analysts and forensic examiners, the skill helps reconstruct Windows file-system timelines, recover deleted file evidence, and detect anti-forensic timestomping, mapping to MITRE ATT&CK techniques T1070.004, T1070.006, and T1005.
- #mft
- #ntfs
- #deleted-files
- #file-recovery
- #dfir
- #forensics