# Parse whole MFT with icat?

**URL:** <https://sleuthkit.discourse.group/t/parse-whole-mft-with-icat/2572>\
**Category:** The Sleuth Kit Help\
**Created:** [April 8, 2021, 11:40am UTC](https://sleuthkit.discourse.group/t/parse-whole-mft-with-icat/2572 "2021-04-08T11:40:22Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Marc\_Martinez\_Soler](https://yyz2.discourse-cdn.com/free1/user_avatar/sleuthkit.discourse.group/marc_martinez_soler/32/338_2.png) [@Marc\_Martinez\_Soler](https://sleuthkit.discourse.group/u/Marc_Martinez_Soler)\
**Post date:** [April 8, 2021, 11:40am UTC](https://sleuthkit.discourse.group/t/parse-whole-mft-with-icat/2572/1 "2021-04-08T11:40:22Z")

</div>

I’m trying to retreive all file offsets and size to be able to reverse locate a file starting with a disk offset.

With icat.exe from sleuthkit it’s possible to view all info from an inode, but there is any way to parse all inodes and get all info in a parseable way?

---

<div class="post-metadata">

**Author:** ![Alan\_Browne](https://yyz2.discourse-cdn.com/free1/user_avatar/sleuthkit.discourse.group/alan_browne/32/960_2.png) [@Alan\_Browne](https://sleuthkit.discourse.group/u/Alan_Browne)\
**Post date:** [April 10, 2021, 1:54pm UTC](https://sleuthkit.discourse.group/t/parse-whole-mft-with-icat/2572/2 "2021-04-10T13:54:18Z")

</div>

One way is to run fiwalk on the disk/image. If you choose to export it out to xml it will display each file, the metadata and the offset to where the file resides on the disk. Fiwalk is part of the sleuthkit
