Do you have EnCase Version 6?
I have a script that will completely decode each MFT record.
Email me and I will forward you a copy.
Ryan,
Have you looked into Grok-NTFS by ASR DATA?
http//
It may provide you with the access and information you're seeking.
Cheers!
farmerdude
Ryan,
Have you looked into Grok-NTFS by ASR DATA?
The link for the download looks like "a polar bear in a snowstorm." Also there is no purchase option. Is it still an active program?
Will this work with WinHex Specialist Edition? If so how do I do this? Also, as noted by BitHead, does anyone know where there is a valid download of Grok-NTFS?
BCOPD4740 - Do you know if that script would work in EnCase 4.2?
I cannot downlod the one from ASR data I may have to look elseware online for the link, thusfar I still cannot get the time and state stamps out (its bieng difficult or I am not pulling the right bytes). I am using WinHex currenty thanks for the help sofar I am still working on it though my job is taking alot of my time at the moment due to hoildays.
Thanks
Ryan
BCOPD4740 - Do you know if that script would work in EnCase 4.2?
I think Technical Services at Guidance Software has one. you should contact them.
To clarify The MFT auto-coloring feature is available in X-Ways Forensics as well as WinHex with a specialist or forensic license.
Stefan