Showing posts with label Master File Table. Show all posts
Showing posts with label Master File Table. Show all posts

Saturday, November 13, 2021

DIGITAL FORENSICS:MFTDump

DIGITAL FORENSICS:MFTDump

MFTDump – Tool to Parse MFT Files

The MFT Master File Table files on NTFS file system are table that will store and provide information about file changes on the hard disk. information may include file size, file name, date and time stamps and more. If you are looking to analyze MFT files you can check MFTDump.
MFTDump is a tool provides a quick and easy way to extract forensic metadata from an NTFS volume $MFT file. It is designed to supplement some forensic tools such as EnCase, FTK, Hex-Ways Forensic, etc.

 

I will pull the $MFT using FTK Imager Lite$MFT.copy0 File. The parse the MFT using MFTDump.

 

#MFTDump_V.1.3.0>mftdump.exe /l /o mft.csv "C:\Users\xxx\Downloads\MFTDump_V.1.3.0\$MFT.copy0"

Identifying alternate data streams (ADS).
#MFTDump_V.1.3.0>mftdump.exe -a "C:\Users\xxx\Downloads\MFTDump_V.1.3.0\$MFT.copy0"

Menu > Data > Text to Columns
 


Jeff Harrison mftdump Extra Credit

 

 

Download MFTDump

How to export Master File Table to csv

When a partition was created/Modify (Master File Table) 

Ref:  

You can read more and download the tool over here: http://malware-hunters.net/freetools/ 
https://sectechno.com/mftdump-tool-to-parse-mft-files/
  • "A Journey into NTFS"
    • Part 1: https://medium.com/@bromiley/a-journey-into-ntfs-part-1-e2ac6a6367ec
    • Part 2: https://medium.com/@bromiley/ntfs-series-2b3b91faaf21
    • Part 3: https://medium.com/@bromiley/a-journey-into-ntfs-part-3-5e197a0cab58
    • Part 4: https://medium.com/@bromiley/a-journey-into-ntfs-part-4-f2865c39ac83
    • Part 5: https://medium.com/@bromiley/ntfs-part-5-13e20588af59
    • Part 6: https://medium.com/@bromiley/ntfs-part-6-43a50fad89f3
    • Part 7: https://medium.com/@bromiley/ntfs-part-7-an-ntfs-story-caf42565855b
  • https://github.com/dkovar/analyzeMFT
  • https://github.com/jschicht/Mft2Csv
  • https://github.com/libyal/libfsntfs/blob/master/documentation/New%20Technologies%20File%20System%20(NTFS).asciidoc
alternate-data-streams-overview
beginning-analysisbeginning-analysis
http://az4n6.blogspot.com/2015/09/
forensics-tools-by-windows-artefact-cheat-sheet

#WindowsForensic #ComputerForensics #dfir #forensics #digitalforensics #computerforensic #investigation #cybercrime #fraud #MobileForensics


หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูลและเพื่อการศึกษาเท่านั้น
* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
ขอบคุณครับ

 

Monday, September 24, 2018

Digital Forensics:How to export Master File Table to csv

Digital Forensics:How to export Master File Table to csv


MFT หรือ Master File Table  คือ

ในระบบจัดการไฟล์แบบ NTFS  นั้น Master File Table (MFT) นั้นเปรียบเสมือนหัวใจหลัก เพราะเป็นส่วนที่ใช้เก็บข้อมูล รายละเอียดของไฟล์และไดเร็กทอรี่ทั้งหมด ภายใน MFT จะเก็บข้อมูล เป็น Entry หรือที่เรียกว่า MFT Entry

MFT Entry จะประกอบไปด้วยหลาย Attribute โดยมี Attribute ที่มีข้อมูล ของไฟล์คือ STANDARD_INFORMATION (0x10 (16)) เก็บข้อมูล รายละเอียดมาตรฐานของ MFT Entry, FILENAME (0x30 (48)) เก็บ ข้อมูลรายละเอียดของไฟล์, DATA (0x80 (128)) เก็บข้อมูลตำแหน่งของ เนื้อไฟล์ข้อมูลที่อยู่บนฮาร์ดดิส์ก
MFT Entry
MFT Entry จะมีขนาดทั้งหมดเท่ากับ 1,024 ไบต์ (Bytes)
เป็นไฟล์ในระบบไฟล์แบบ NTFS โดยจะรวบรวมข้อมูลของไฟล์ทั้งหมดในไดร์ฟนั้นๆ  การตรวจสอบไฟล์ $MFT จึงมีประโยชน์อย่างมากในช่วยค้นหาไฟล์ที่ถูกลบเพื่อทำการกู้คืนและการใช้วิเคราะห์ในฐานะของหลักฐานดิจิทัลรูปแบบหนึ่ง
MFT Entry  1,024  Bytes

โดยปกติไฟล์ $MFT จะถูกสร้างขึ้นโดยอัตโนมัติเมื่อมีการฟอร์แมตหรือConvert พาร์ติชันของดิสก์เป็น NTFS โดยวันที่และเวลาที่ไฟล์ $MFT ถูกสร้างขึ้น (หรือวันที่และเวลาที่ดิสก์ถูกฟอร์แมต) จะถูกระบุอยู่ในคุณลักษณะของไฟล์ $MFT ที่หัวข้อ Date created ซึ่งในกรณีโดยส่วนใหญ่ที่ดิสก์ดังกล่าวถูกติดตั้งระบบปฏิบัติการ ไฟล์ของระบบปฏิบัติการจะมีวันที่และเวลาที่ถูกสร้างใกล้เคียงหรือสอดคล้องกับค่า Date created ใน $MFT

แนะนำเครื่องมือสำหรับวิเคราะห์ Master File Table   (MFT analysis free Tools)
1. FTK Imager    
2. MFT Explorer 
3. MFTECmd
4. Mft2csv
5. Timeline Explorer 

Step 1 Export $MFT  ใช้โปรแกรม FTK Imager  Export file $MFT 

FTK Imager  export File $MFT
FTK Imager    สำหรับ export File $MFT

 Step 2   $MFT Export to csv


Step 3 Preview $MFT       ใช้ โปรแกรม MFT Explorer เปิด file  $MFT  

MFT Explorer


 Step 4 Export $MFT    to CSV


 Mft2csv Export csv > 
    - Choose $MFT
    - Set Outout Path
    - Start Processing 
Mft2csv Export csv
OutPut Csv file
MFTECmd Export csv > 
 
 MFTECmd.exe -f "F:\$MFT" --csv "c:\temp"

Examples: 
          MFTECmd.exe -f "C:\Temp\SomeMFT" --csv "c:\temp\out" --csvf MyOutputFile.csv
          MFTECmd.exe -f "C:\Temp\SomeMFT" --csv "c:\temp\out"
          MFTECmd.exe -f "C:\Temp\SomeMFT" --json "c:\temp\jsonout"
          MFTECmd.exe -f "C:\Temp\SomeMFT" --body "c:\temp\bout" --bdl c
          MFTECmd.exe -f "C:\Temp\SomeMFT" --de 5-5

MFTECmd option

Csv file

Step 5   Import csv to Timeline Explorer 


ใช้ Timeline Explorer สามารถแสดงวันเวลา Timestamp โดยเปิดไฟล์จาก CSV ได้

    เมื่อได้ csv file มาแล้วให้ใช้ Timeline Explorer  import csv file เพื่อค้นหาไฟล์และดูวันเวลาที่สงสัย 
Last Access
Suspect File


สรุป 
 เราสามารถใช้ Free Tools ช่วยในการวิเคราะห์ MFT หรือ Master File Table  


Last Update 24-9-2019

Resident Data

Ref:

https://www.andreafortuna.org/2017/07/18/how-to-extract-data-and-timeline-from-master-file-table-on-ntfs-filesystem/
https://github.com/jschicht
https://forensicswiki.org/wiki/Encase_image_file_format
https://www.andreafortuna.org/2017/07/18/how-to-extract-data-and-timeline-from-master-file-table-on-ntfs-filesystem/
https://binaryforay.blogspot.com/2018/06/introducing-mftecmd.html
https://whereismydata.wordpress.com/2009/06/05/forensics-what-is-the-mft/
https://ericzimmerman.github.io/#!index.md
https://dforensicexaminer.wordpress.com/2019/03/31/new-technologies-file-system-ntfs/
https://www.i-secure.co.th/2019/07/forensic-analysis-mft/

หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูลและเพื่อการศึกษาเท่านั้น

* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
ขอบคุณครับ


#WindowsForensic #ComputerForensics #dfir #forensics #digitalforensics #computerforensic #investigation #cybercrime #fraud


Sunday, October 7, 2012

Digital Forensics:When a partition was created/Modify (Master File Table)

Digital Forensics:When a partition was created/Modify (Master File Table)


 วันนี้มาดูวิธีตรวจสอบ เวลาที่พาร์ติชั่นถูกสร้างขึ้นและวันเวลาที่ติดตั้ง windows

MFT หรือ Master File Table เป็นไฟล์ในระบบไฟล์แบบ NTFS โดยจะรวบรวมข้อมูลของไฟล์ รายละเอียดของไฟล์และไดเร็กทอรี่ทั้งหมด ในไดร์ฟนั้นๆ

ตัวอย่างที่ 1 $MFT  Master File Table   Date Create 26-3-2012

ตัวอย่างที่ 1 Windows XP 

$MFT  Master File Table   Date Create 26-3-2012

                                          Date Modify 26-3-2012

                                          Date Access 26-3-2012

โดยปกติไฟล์ $MFT จะถูกสร้างขึ้นโดยอัตโนมัติเมื่อมีการฟอร์แมตหรือเปลี่ยนพาร์ติชันของดิสก์เป็น NTFS โดยวันที่และเวลาที่ไฟล์ $MFT ถูกสร้างขึ้น (หรือวันที่และเวลาที่ดิสก์ถูกฟอร์แมต) จะถูกระบุอยู่ในคุณลักษณะของไฟล์ $MFT ที่หัวข้อ Date created ซึ่งในกรณีโดยส่วนใหญ่ที่ดิสก์ดังกล่าวถูกติดตั้งระบบปฏิบัติการ ไฟล์ของระบบปฏิบัติการจะมีวันที่และเวลาที่ถูกสร้างใกล้เคียงหรือสอดคล้องกับค่า Date created ใน $MFT ตามรูปภาพ ตัวอย่างที่ 1

Original Install Date:
Windows Original Install Date: 26-3-2012

ตัวอย่างที่ 2 Windows Original Install Date: 24-9-2019    

ตัวอย่างที่ 2  Windows 7 Professional 

$MFT  Master File Table   Date Create: 24-9-2019

           Windows Original Install Date:     24-9-2019                         


จุดสังเกต
 1 .  $MFT  Master File Table   (MAC TIme)
 2.  Systeminfo (Original Install Date)
 3.  Volume Serial Number  ของ Partition



อ่านเพิ่มเต้ิม

หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูลและเพื่อการศึกษาเท่านั้น

* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
ขอบคุณครับ

#WindowsForensic #ComputerForensics #dfir #forensics #digitalforensics #computerforensic #investigation #cybercrime #fraud

Volatility Lab

Volatility Lab  Image Wanna.vmem P.73 windows.info #python3  vol.py   -f '/home/kali/Desktop/Wanna/Wanna-MEM.vmem' windows.info     ...