Notifications
Clear all

$Logfile (NTFS)

3 Posts
2 Users
0 Reactions
656 Views
iruiper
(@iruiper)
Estimable Member
Joined: 20 years ago
Posts: 145
Topic starter   [#932]

Does anyone know how to extract usefuld data in a forensic investigation from the $logfile hidden file in a NTFS file system?



   
Quote
keydet89
(@keydet89)
Famed Member
Joined: 22 years ago
Posts: 3568
 

Yes. Start with Brian Carrier's "File System Forensics" book.

Is there anything in particular that you're looking for?

Harlan



   
ReplyQuote
iruiper
(@iruiper)
Estimable Member
Joined: 20 years ago
Posts: 145
Topic starter  

Mmmm… nope. Nothing in concrete. I just wanted to know what kind of information I could find inside and how to extract it. Thank you for the recommendation on the book 😉



   
ReplyQuote
Share: