Notifications
Clear all

$MFT analysis

7 Posts
5 Users
0 Reactions
791 Views
(@research1)
Estimable Member
Joined: 17 years ago
Posts: 165
Topic starter  

I'm looking for a Doc on how to find the data of where the $MFT entries point too, I don't have my Encase book at hand.

Could someone point me in the right direction?

Regards,


   
Quote
keydet89
(@keydet89)
Famed Member
Joined: 21 years ago
Posts: 3568
 

Brian Carrier's book, "File System Forensic Analysis"


   
ReplyQuote
(@research1)
Estimable Member
Joined: 17 years ago
Posts: 165
Topic starter  

Thanks keydet89, I'm looking more for an on-line white paper which I can read now.


   
ReplyQuote
benfindlay
(@benfindlay)
Estimable Member
Joined: 16 years ago
Posts: 142
 

Sammes and Jenkinson's book "Forensic Computing A Practitioner's Guide" has a very useful chapter on this and is available on Google Books.

It also has worked examples you can follow which I personally found really useful

HTH

Ben


   
ReplyQuote
(@douglasbrush)
Prominent Member
Joined: 16 years ago
Posts: 812
 

When I searched Google
http//www.google.com/search?q=mft+forensic+analysis&ie=utf-8&oe=utf-8&aq=t&rls=org.mozillaen-USofficial&client=firefox-a

I found several blogs and sites. Where is my data has a nice brief
http//whereismydata.wordpress.com/2009/06/05/forensics-what-is-the-mft/

Also might want to check the Advanced Google searches. Pretty cool because you can do a global search for file types
MFT forensic PDF search

And there you will find several papers on MFT analysis.

Do take the time in the future to read, re-read and read some more Brians book on NTFS and MTF. It is stuff that you really want to understand by heart.


   
ReplyQuote
ehuber
(@ehuber)
Trusted Member
Joined: 17 years ago
Posts: 91
 

Thanks keydet89, I'm looking more for an on-line white paper which I can read now.

Buy it on the Kindle. You can get a Kindle App for pretty much every platform these days including a PC.


   
ReplyQuote
(@research1)
Estimable Member
Joined: 17 years ago
Posts: 165
Topic starter  

Thanks Chaps. Job done.


   
ReplyQuote
Share: