Notifications
Clear all

A $I30 index tool

5 Posts
3 Users
0 Reactions
3,061 Views
(@segevrl)
New Member
Joined: 4 years ago
Posts: 3
Topic starter  

https://github.com/harelsegev/INDXRipper

Find index entries in NTFS $I30 attributes and easily integrate the data into a timeline

This started as an experimental project, but turned out to be useful enough to share


   
Quote
jaclaz
(@jaclaz)
Illustrious Member
Joined: 17 years ago
Posts: 5133
 

Nice.

Another little tool that goes in the toolbox, just in case. 

jaclaz


   
ReplyQuote
(@segevrl)
New Member
Joined: 4 years ago
Posts: 3
Topic starter  

@jaclaz Ideally, it should always be used when making a file system timeline. It finds files other tools don't, and it does it fairly quickly.


   
ReplyQuote
(@thefuf)
Reputable Member
Joined: 17 years ago
Posts: 262
 

@segevrl, what about dfir_ntfs?


   
ReplyQuote
(@segevrl)
New Member
Joined: 4 years ago
Posts: 3
Topic starter  

@thefuf I've never tried it. It looks great, honestly. It seems like it carves $FILE_NAME attributes from the slack space of $INDEX_ALLOCATION attributes, which is similar to what INDXRipper is doing. I guess you can use either of them for this purpose.


   
ReplyQuote
Share: