Notifications
Clear all

A $I30 index tool

5 Posts
3 Users
0 Reactions
4,606 Views
(@segevrl)
New Member
Joined: 5 years ago
Posts: 3
Topic starter   [#19112]

https://github.com/harelsegev/INDXRipper

Find index entries in NTFS $I30 attributes and easily integrate the data into a timeline

This started as an experimental project, but turned out to be useful enough to share



   
Quote
jaclaz
(@jaclaz)
Illustrious Member
Joined: 19 years ago
Posts: 5133
 

Nice.

Another little tool that goes in the toolbox, just in case. 

jaclaz



   
ReplyQuote
(@segevrl)
New Member
Joined: 5 years ago
Posts: 3
Topic starter  

@jaclaz Ideally, it should always be used when making a file system timeline. It finds files other tools don't, and it does it fairly quickly.



   
ReplyQuote
(@thefuf)
Reputable Member
Joined: 18 years ago
Posts: 262
 

@segevrl, what about dfir_ntfs?



   
ReplyQuote
(@segevrl)
New Member
Joined: 5 years ago
Posts: 3
Topic starter  

@thefuf I've never tried it. It looks great, honestly. It seems like it carves $FILE_NAME attributes from the slack space of $INDEX_ALLOCATION attributes, which is similar to what INDXRipper is doing. I guess you can use either of them for this purpose.



   
ReplyQuote
Share: