$MFT help trying to...
 
Notifications
Clear all

$MFT help trying to deconstruct.

18 Posts
11 Users
0 Reactions
1,522 Views
(@bcopd4740)
Active Member
Joined: 17 years ago
Posts: 14
 

Do you have EnCase Version 6?

I have a script that will completely decode each MFT record.

Email me and I will forward you a copy.


   
ReplyQuote
(@farmerdude)
Estimable Member
Joined: 20 years ago
Posts: 242
 

Ryan,

Have you looked into Grok-NTFS by ASR DATA?

http//www.asrdata.com/Grok-NTFS/

It may provide you with the access and information you're seeking.

Cheers!

farmerdude

www.forensicbootcd.com

www.onlineforensictraining.com


   
ReplyQuote
(@bithead)
Noble Member
Joined: 20 years ago
Posts: 1206
 

Ryan,

Have you looked into Grok-NTFS by ASR DATA?

The link for the download looks like "a polar bear in a snowstorm." Also there is no purchase option. Is it still an active program?


   
ReplyQuote
(@mmachor)
Trusted Member
Joined: 17 years ago
Posts: 70
 

Will this work with WinHex Specialist Edition? If so how do I do this? Also, as noted by BitHead, does anyone know where there is a valid download of Grok-NTFS?


   
ReplyQuote
(@mmachor)
Trusted Member
Joined: 17 years ago
Posts: 70
 

BCOPD4740 - Do you know if that script would work in EnCase 4.2?


   
ReplyQuote
(@xaberx)
Estimable Member
Joined: 17 years ago
Posts: 105
Topic starter  

I cannot downlod the one from ASR data I may have to look elseware online for the link, thusfar I still cannot get the time and state stamps out (its bieng difficult or I am not pulling the right bytes). I am using WinHex currenty thanks for the help sofar I am still working on it though my job is taking alot of my time at the moment due to hoildays.

Thanks
Ryan


   
ReplyQuote
_nik_
(@_nik_)
Trusted Member
Joined: 19 years ago
Posts: 93
 

BCOPD4740 - Do you know if that script would work in EnCase 4.2?

I think Technical Services at Guidance Software has one. you should contact them.


   
ReplyQuote
 sfxw
(@sfxw)
Active Member
Joined: 17 years ago
Posts: 14
 

To clarify The MFT auto-coloring feature is available in X-Ways Forensics as well as WinHex with a specialist or forensic license.

Stefan


   
ReplyQuote
Page 2 / 2
Share: