We can use the MFT to investigate data and find detailed information about files. NTFS uses the Master File Table (MFT) as a database to keep track of files. This article describes, in a straightforward manner, the process of extracting NTFS file system data from a physical device. Familiarity with the normal layout of a Windows File System.How to recover file data with FTK Imager.How to locate file artifacts and metadata within the Master File Table.
One of the most important tasks of a computer forensics expert is making file artifacts and metadata visible. The Master File Table or MFT can be considered one of the most important files in the NTFS file system, as it keeps records of all files in a volume, the physical location of the files on the drive and file metadata.