Notifications
Clear all

EnCase Vs FTK

3 Posts
3 Users
0 Reactions
650 Views
(@tootypeg111)
New Member
Joined: 18 years ago
Posts: 1
Topic starter  

I have a problem. In imaging a recycler folder, FTK returned 1 more file than EnCase. This file was named '$I30' and it appeared to contain a huge list of deleted files? However im not sure if this correct. Does anyone actually know wat this file does? Thanks


   
Quote
(@dietro)
Trusted Member
Joined: 20 years ago
Posts: 51
 

A detailed description of $I30 can be found HERE.


   
ReplyQuote
_nik_
(@_nik_)
Trusted Member
Joined: 19 years ago
Posts: 93
 

This file was named '$I30' Does anyone actually know wat this file does? Thanks

In EnCase the contents of this file do get attributed to a directory/folder.
The $I30 stream for a folder contains the files that are in it, organized as a b-tree. There is also some slack/deleted information in it!


   
ReplyQuote
Share: