Загрузка страницы

Anatomy of an NTFS FILE Record - Windows File System Forensics

In this episode, we'll talk about the structure and composition of an NTFS FILE record. Then, we'll take a look at a sample record for a resident file and learn how to manually extract the important attributes.

*** If you enjoy this video, please consider supporting 13Cubed on Patreon at patreon.com/13cubed. ***

📖 Chapters

00:00 - Intro
02:08 - Analysis

🛠 Resources

Anatomy of an NTFS File Record (Cheat Sheet):
https://drive.google.com/file/d/1UBOu2BXeBz7R6dzjUG2wo-xZrZO82HPg/view?usp=share_link

Everything I know about NTFS (primary reference for this episode):
https://kcall.co.uk/ntfs/

010 Editor:
https://www.sweetscape.com/010editor/

#Forensics #DigitalForensics #DFIR #ComputerForensics #WindowsForensics

Видео Anatomy of an NTFS FILE Record - Windows File System Forensics канала 13Cubed
Показать
Комментарии отсутствуют
Введите заголовок:

Введите адрес ссылки:

Введите адрес видео с YouTube:

Зарегистрируйтесь или войдите с
Информация о видео
13 июня 2022 г. 17:09:02
00:11:45
Яндекс.Метрика