I'm looking for a Doc on how to find the data of where the $MFT entries point too, I don't have my Encase book at hand.
Could someone point me in the right direction?
Regards,
Brian Carrier's book, "File System Forensic Analysis"
Thanks keydet89, I'm looking more for an on-line white paper which I can read now.
Sammes and Jenkinson's book "Forensic Computing A Practitioner's Guide" has a very useful chapter on this and is available on Google Books.
It also has worked examples you can follow which I personally found really useful
HTH
Ben
When I searched Google
I found several blogs and sites. Where is my data has a nice brief
http//
Also might want to check the Advanced Google searches. Pretty cool because you can do a global search for file types
And there you will find several papers on MFT analysis.
Do take the time in the future to read, re-read and read some more Brians book on NTFS and MTF. It is stuff that you really want to understand by heart.
Thanks keydet89, I'm looking more for an on-line white paper which I can read now.
Buy it on the
Thanks Chaps. Job done.