Notifications
Clear all

MFT Data Runs

2 Posts
2 Users
0 Reactions
1,073 Views
(@nathan14280)
New Member
Joined: 1 year ago
Posts: 1
Topic starter  

I need to do a data run (0x80) and i need to show the calculations of starting cluster number, number of clusters. How should i do this? it also says to carefully consider the VCN while calculating the starting position of cluster. I have an image of the MFT file record but am unsure how to attach it to this post.

 

Thanks


   
Quote
JimC
 JimC
(@jimc)
Estimable Member
Joined: 8 years ago
Posts: 86
 

Microsoft call MFT data runs "mapping pairs". In some texts, they are called data runs or extents.

For a general overview of how MFT mapping pairs work, I would suggest checking p280 of Brian Carrier's excellent book "File System Forensic Analysis".

For a practical example of how the data can be decoded, I would suggest you look at Appendix A9 (p396) in Samme's and Jenkinson's book "Forensic Computing: A practitioner's guide" (2nd edition).

Both books are available on Amazon.

Finally, Microsoft themselves document it here:

https://learn.microsoft.com/en-gb/windows/win32/devnotes/attribute-record-header

 

Jim

forensicinternals.com

 


   
ReplyQuote
Share: