AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
SKILL verified Apache-2.0 Self-run

Analyzing Mft For Deleted File Recovery

skill-mukul975-anthropic-cybersecurity-skills-analyzing-mft-for-deleted-file-recovery · by mukul975

Analyze the NTFS Master File Table ($MFT) to recover metadata and content

No reviews yet
0 installs
38 views
0.0% view→install

Install

$ agentstack add skill-mukul975-anthropic-cybersecurity-skills-analyzing-mft-for-deleted-file-recovery

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access Used
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/skill-mukul975-anthropic-cybersecurity-skills-analyzing-mft-for-deleted-file-recovery)

Reliability & compatibility

Security review passed
0 installs to date
no reviews yet
2mo ago

Declared compatibility

Claude CodeClaude Desktop

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Analyzing Mft For Deleted File Recovery? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

Analyzing MFT for Deleted File Recovery

Overview

The NTFS Master File Table ($MFT) is the central metadata repository for every file and directory on an NTFS volume. Each file is represented by at least one 1024-byte MFT record containing attributes such as $STANDARDINFORMATION (timestamps, permissions), $FILENAME (name, parent directory, timestamps), and $DATA (file content or cluster run pointers). When a file is deleted, its MFT record is marked as inactive (InUse flag cleared) but the metadata remains until the entry is reallocated by a new file. This persistence makes MFT analysis a primary technique for recovering deleted file evidence, reconstructing file system timelines, and detecting anti-forensic activity such as timestomping.

When to Use

  • When investigating security incidents that require analyzing mft for deleted file recovery
  • When building detection rules or threat hunting queries for this domain
  • When SOC analysts need structured procedures for this analysis type
  • When validating security monitoring coverage for related attack techniques

Prerequisites

  • Forensic disk image (E01, raw/dd, VMDK, or VHDX format)
  • MFTECmd (Eric Zimmerman) or analyzeMFT (Python-based)
  • FTK Imager, Arsenal Image Mounter, or similar for image mounting
  • Timeline Explorer or Excel for CSV analysis
  • Python 3.8+ for custom analysis scripts
  • Understanding of NTFS file system internals

MFT Structure and Record Layout

MFT Record Header

Each MFT record begins with the signature "FILE" (0x46494C45) and contains:

| Offset | Size | Field | |--------|------|-------| | 0x00 | 4 bytes | Signature ("FILE") | | 0x04 | 2 bytes | Offset to update sequence | | 0x06 | 2 bytes | Size of update sequence | | 0x08 | 8 bytes | $LogFile sequence number | | 0x10 | 2 bytes | Sequence number | | 0x12 | 2 bytes | Hard link count | | 0x14 | 2 bytes | Offset to first attribute | | 0x16 | 2 bytes | Flags (0x01 = InUse, 0x02 = Directory) | | 0x18 | 4 bytes | Used size of MFT record | | 0x1C | 4 bytes | Allocated size of MFT record | | 0x20 | 8 bytes | Base file record reference | | 0x28 | 2 bytes | Next attribute ID |

Key MFT Attributes

| Type ID | Name | Description | |---------|------|-------------| | 0x10 | $STANDARDINFORMATION | Timestamps, flags, owner ID, security ID | | 0x30 | $FILENAME | Filename, parent MFT reference, timestamps | | 0x40 | $OBJECTID | Unique GUID for the file | | 0x50 | $SECURITYDESCRIPTOR | ACL permissions | | 0x60 | $VOLUMENAME | Volume label (volume metadata files only) | | 0x80 | $DATA | File content (resident if 0x20 and c < 0x7F for c in slack[:50]): slackfindings.append({ "record": recordnum, "usedsize": usedsize, "slacksize": recordsize - usedsize, "slack_preview": slack[:100].hex() })

record_num += 1

return slack_findings


## Correlation with Supporting Artifacts

### Cross-Reference MFT with $Recycle.Bin

```powershell
# Parse Recycle Bin with RBCmd
RBCmd.exe -d "C:\Evidence\$Recycle.Bin" --csv C:\Output --csvf recycle_bin.csv

# Correlate: $I files contain original path and deletion timestamp
# Match MFT entry numbers from $R files back to original MFT records

Cross-Reference MFT with Volume Shadow Copies

# List volume shadow copies
vssadmin list shadows

# Mount shadow copies and extract $MFT from each
# Compare MFT records across shadow copies to track file changes over time

Forensic Value

  • Deleted file metadata recovery: Original filename, path, size, and timestamps
  • Timeline reconstruction: File creation, modification, access, and deletion events
  • Timestomping detection: Comparing $SI vs $FN timestamps
  • Data carving guidance: MFT cluster runs point to file content on disk
  • Anti-forensic detection: Identifying wiped or manipulated MFT records

References

  • NTFS MFT Advanced Forensic Analysis: https://www.deaddisk.com/posts/ntfs-mft-advanced-forensic-analysis-guide/
  • MFT Slack Space Forensic Value: https://www.sygnia.co/blog/the-forensic-value-of-mft-slack-space/
  • MFTECmd Documentation: https://ericzimmerman.github.io/
  • SANS FOR500: Windows Forensic Analysis

Example Output

$ MFTECmd.exe -f "C:\Evidence\$MFT" --csv /analysis/mft_output

MFTECmd v1.2.2 - MFT Parser
==============================
Input: C:\Evidence\$MFT (Size: 384 MB)
Total MFT Entries: 395,264

Parsing MFT entries... Done (12.4 seconds)

--- Deleted File Recovery Summary ---
Total Entries:          395,264
Active Files:           245,832
Deleted Files:          149,432
  Recoverable:          87,234 (resident data or clusters not reallocated)
  Partially Recoverable: 31,456 (some clusters overwritten)
  Unrecoverable:        30,742 (all clusters reallocated)

--- Recently Deleted Files (Incident Window: 2024-01-15 to 2024-01-18) ---
MFT Entry | Filename                          | Path                               | Size      | Deleted (UTC)         | Recoverable
----------|-----------------------------------|------------------------------------|-----------|-----------------------|------------
148923    | exfil_tool.exe                    | C:\ProgramData\Updates\            | 1,258,496 | 2024-01-17 02:45:12   | YES
148924    | exfil_tool.log                    | C:\ProgramData\Updates\            | 45,312    | 2024-01-17 02:45:14   | YES
149001    | passwords.txt                     | C:\Users\jsmith\Desktop\           | 2,048     | 2024-01-17 02:50:33   | YES
149150    | scan_results.csv                  | C:\Users\jsmith\AppData\Local\Temp | 892,416   | 2024-01-17 03:00:01   | PARTIAL
149200    | mimikatz.exe                      | C:\Windows\Temp\                   | 1,250,816 | 2024-01-18 01:15:22   | YES
149201    | sekurlsa.log                      | C:\Windows\Temp\                   | 32,768    | 2024-01-18 01:15:25   | YES
149302    | .bash_history                     | C:\Users\jsmith\                   | 4,096     | 2024-01-18 03:00:00   | NO
149400    | ClearEventLogs.ps1                | C:\Windows\Temp\                   | 1,536     | 2024-01-18 03:01:12   | YES

--- $STANDARD_INFORMATION vs $FILE_NAME Timestamp Analysis (Timestomping Detection) ---
MFT Entry | Filename            | $SI Created          | $FN Created          | Delta     | Verdict
----------|---------------------|----------------------|----------------------|-----------|----------
148923    | exfil_tool.exe      | 2023-06-15 10:00:00  | 2024-01-15 14:34:02  | -214 days | TIMESTOMPED
149200    | mimikatz.exe        | 2022-01-01 00:00:00  | 2024-01-16 02:30:15  | -745 days | TIMESTOMPED

Recovered files exported to: /analysis/mft_output/recovered/
Full CSV report: /analysis/mft_output/mft_analysis.csv (395,264 rows)
Timeline CSV: /analysis/mft_output/mft_timeline.csv

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.