Anatomy of an NTFS FILE Record - Windows File System Forensics
In this episode, we'll talk about the structure and composition of an NTFS FILE record. Then, we'll take a look at a sample record for a resident file and learn how to manually extract the important attributes.
*** If you enjoy this video, please consider supporting 13Cubed on Patreon at patreon.com/13cubed. ***
📖 Chapters
00:00 - Intro
02:08 - Analysis
🛠 Resources
Anatomy of an NTFS File Record (Cheat Sheet):
https://drive.google.com/file/d/1UBOu2BXeBz7R6dzjUG2wo-xZrZO82HPg/view?usp=share_link
Everything I know about NTFS (primary reference for this episode):
https://kcall.co.uk/ntfs/
010 Editor:
https://www.sweetscape.com/010editor/
#Forensics #DigitalForensics #DFIR #ComputerForensics #WindowsForensics
Видео Anatomy of an NTFS FILE Record - Windows File System Forensics канала 13Cubed
*** If you enjoy this video, please consider supporting 13Cubed on Patreon at patreon.com/13cubed. ***
📖 Chapters
00:00 - Intro
02:08 - Analysis
🛠 Resources
Anatomy of an NTFS File Record (Cheat Sheet):
https://drive.google.com/file/d/1UBOu2BXeBz7R6dzjUG2wo-xZrZO82HPg/view?usp=share_link
Everything I know about NTFS (primary reference for this episode):
https://kcall.co.uk/ntfs/
010 Editor:
https://www.sweetscape.com/010editor/
#Forensics #DigitalForensics #DFIR #ComputerForensics #WindowsForensics
Видео Anatomy of an NTFS FILE Record - Windows File System Forensics канала 13Cubed
Показать
Комментарии отсутствуют
Информация о видео
Другие видео канала
![An Important Change to ShellBags - Windows 11 2023 Update!](https://i.ytimg.com/vi/M1nyMIu1Y18/default.jpg)
![VMware Memory Forensics - Don't Miss This Important Detail!](https://i.ytimg.com/vi/P0yw93GJsYU/default.jpg)
![Investigating Windows Memory Is Here!](https://i.ytimg.com/vi/IIfHov1W2ko/default.jpg)
![Old School MS-DOS Commands for DFIR](https://i.ytimg.com/vi/SfG25LmNkT0/default.jpg)
![Detecting PsExec Usage](https://i.ytimg.com/vi/oVM1nQhDZQc/default.jpg)
![A File's Life - File Deletion and Recovery](https://i.ytimg.com/vi/4zlk9ZSMa-4/default.jpg)
![Two Thumbs Up - Thumbnail Forensics](https://i.ytimg.com/vi/5efCp1VXhfQ/default.jpg)
![Interview with Lesley Carhart (hacks4pancakes)](https://i.ytimg.com/vi/aC4jd8hQdYo/default.jpg)
![It's About Time - Timestamp Changes in Windows 11](https://i.ytimg.com/vi/_D2vJZvCW_8/default.jpg)
![Digital Forensics Training You Can Actually Afford!](https://i.ytimg.com/vi/d8fAKTXOjS8/default.jpg)
![EZ Tools Manuals Interview with Andrew Rathbun](https://i.ytimg.com/vi/Mz5hin8Wxak/default.jpg)
![A New Program Execution Artifact - Windows 11 22H2 Update!](https://i.ytimg.com/vi/rV8aErDj06A/default.jpg)
![The Dissect Effect - An Open Source IR Framework](https://i.ytimg.com/vi/A2e203LizAM/default.jpg)
![Let's Talk About MUICache](https://i.ytimg.com/vi/ea2nvxN878s/default.jpg)
![How Many Timestamps??? #Shorts](https://i.ytimg.com/vi/xeevyCqC62E/default.jpg)
![Impacket Impediments - Finding Evil in Event Logs](https://i.ytimg.com/vi/UMogme3rDRA/default.jpg)
![What's on My DFIR Box?](https://i.ytimg.com/vi/-xGfzCT6TUQ/default.jpg)
![The Case of the Disappearing Scheduled Task](https://i.ytimg.com/vi/xrd0w505aS8/default.jpg)
![Windows Hibernation Files - A Look Back in Time](https://i.ytimg.com/vi/Kbw1sDJb61g/default.jpg)
![Let's Talk About NTFS Index Attributes](https://i.ytimg.com/vi/x-M-wyq3BXA/default.jpg)