Interactive partition map of a Windows boot disk — MBR and GPT layouts, the EFI System Partition and the boot chain. Click any partition, folder or file to inspect its forensic role.
The colours below are the five things a Windows boot disk is made of. ESP is the EFI System Partition — a small FAT32 volume holding the boot loaders the firmware runs, and the one partition an attacker can modify to gain control before Windows exists. Windows (C:) is the NTFS volume everything else on this site is about. Recovery holds the Windows Recovery Environment, which can read and write C: without booting it. MSR, the Microsoft Reserved partition, holds no filesystem at all: it is spare space reserved for later use, so anything found in it is out of place. MBR / GPT header is the partition table itself, at the very start of the disk. Unallocated is space claimed by no partition — which is where a deleted partition's data still sits, and where data can be hidden outside any filesystem.
The files on this disk are only the first leg of the relay. Firmware reads the ESP → bootmgfw.efi → winload.efi → the kernel ntoskrnl.exe, which creates System (PID 4) and the first user-mode process, smss.exe. From there the boot stops being a list of files and becomes a living process tree — showing which file owns the first process, when each runs, and what it is responsible for.
Crow-Eye images and parses the disk you just explored — the ESP, the GPT, and the boot-critical files — and flags rogue .efi binaries, partition anomalies, and bootkit indicators.
The layout tells you how the machine was built and how it starts. Three things it does not tell you:
GPT with an ESP means the machine was installed in UEFI mode; MBR means it was installed in legacy or CSM mode. Modern firmware supports both, so an MBR disk in 2026 says the install was legacy — possibly a deliberate choice to avoid Secure Boot — not that the hardware is old.
The table describes the partitions that are declared. It does not describe a deleted partition whose data is still on the platter, a volume hidden inside unallocated space, or anything written between the GPT header and the first partition. A clean-looking table is a statement about the table.
The ESP is a FAT32 volume with no access control once the disk is read outside Windows. Its contents can be replaced by anything that can write to the disk offline. That the expected loaders are present proves they are present; whether they are the ones Microsoft signed is a question of hashes and signatures, not of layout.
What it is genuinely good for: knowing where to look before the filesystem is mounted. The layout tells you which partition holds the boot chain, which holds the evidence, which is reserved and should be empty, and how much of the disk belongs to nothing at all — and all four are visible from the raw device, on a machine that will not boot.
MBR keeps its partition table in the first sector and is limited to four primary partitions and 2 TB disks. GPT stores a larger table with a backup copy at the end of the disk and is what modern UEFI systems use, so which scheme a disk uses tells you a good deal about its age and firmware.
A small FAT32 partition holding the bootloaders the firmware launches. On a Windows UEFI disk it contains the Windows Boot Manager, which makes it the place to look when investigating tampering with the boot path.
Because everything before the operating system runs is beneath the tools that run inside it. Unallocated gaps between partitions, a modified boot record and an unexpected bootloader all live here, and none of them are visible from a normal file listing.
In the Boot Configuration Data store - on the EFI System Partition for UEFI systems, and in the system-reserved partition on older BIOS/MBR installs. It records what is booted and with which options, including whether protections were disabled.