Master File Table analysis
Another technique that can be leveraged for timeline analysis is utilizing external tools to analyze the MFT. Autopsy allows the analyst to export the MFT for analysis using third-party tools. In this case, we will use MFT Explorer, one of several tools developed by Eric Zimmerman.
Eric Zimmerman's tools
Eric Zimmerman is a former FBI agent, SANS course developer, and digital forensics expert. He has created a suite of tools for carving and analyzing data available at https://ericzimmerman.github.io/#!index.md. Additionally, the SANS Institute has created a cheat sheet for the tools available at https://www.sans.org/posters/eric-zimmerman-tools-cheat-sheet/.
In this instance, we will look at processing the MFT from the image that was examined with Autopsy. The MFT can be found within the root directory of the filesystem. Find the $MFT
file, right-click it, select Extract Files, and then save the file to an evidence drive. As good practice, change...