This is a simple GUI to FSCTL_GET_RETRIEVAL_POINTERS Microsoft API.
The idea is to read all clusters belonging to a file, then map these clusters on the logical drive where this file is located, and from there re assemble all clusters and save them to a new destination file.
Thanks to this method, one can save/copy a file which is in use since we « raw » read clusters from a logical drive.
This has been tested with success on \boot\bcd and \windows\system32\config\sam, files which you cannot copy in a « normal » mode.
Beware that using this method, you could end up with a corrupted dump since the file could be modified while you are reading it.