Notifications
Clear all

$Logfile (NTFS)

3 Posts
2 Users
0 Reactions
509 Views
iruiper
(@iruiper)
Estimable Member
Joined: 19 years ago
Posts: 145
Topic starter  

Does anyone know how to extract usefuld data in a forensic investigation from the $logfile hidden file in a NTFS file system?


   
Quote
keydet89
(@keydet89)
Famed Member
Joined: 21 years ago
Posts: 3568
 

Yes. Start with Brian Carrier's "File System Forensics" book.

Is there anything in particular that you're looking for?

Harlan


   
ReplyQuote
iruiper
(@iruiper)
Estimable Member
Joined: 19 years ago
Posts: 145
Topic starter  

Mmmm… nope. Nothing in concrete. I just wanted to know what kind of information I could find inside and how to extract it. Thank you for the recommendation on the book 😉


   
ReplyQuote
Share: