MFT Recycle Bin Ana...
 
Notifications
Clear all

MFT Recycle Bin Analysis - Windows 10

4 Posts
4 Users
0 Likes
1,139 Views
(@tyyphoon)
Posts: 2
New Member
Topic starter
 

Hello all,

I am a newer forensic analyst and have had a question that keeps bugging me. When an entity stages a file in the Recycle Bin and executes it from there or deletes it from there, without it being on the regular file system will there be an MFT entry for said file?

For example, an entity exploits a Windows system and creates Netcat in the Recycle Bin, and executes it to transfer files to an external host. Will the MFT have an entry for the file if the entry has not been written over?

I also understand that when a file is deleted the MFT entry is marked as available, in a normal Windows 10 computer that is used daily is it safe to say the entry would be overwritten within 24 hrs after deletion?

Thank you for all the help, I do apologize if my wording is confusing or it seems trivial.

 
Posted : 01/12/2021 2:44 pm
JimC
 JimC
(@jimc)
Posts: 86
Estimable Member
 

The recycle bin is just an artefact of the user interface. From a file system perspective, it just a regular folder and everything in it will have a $MFT entry in the usual way.

 

Jim

www.binarymarkup.com

 
Posted : 01/12/2021 4:51 pm
Bunnysniper
(@bunnysniper)
Posts: 257
Reputable Member
 
Posted by: @tyyphoon

I also understand that when a file is deleted the MFT entry is marked as available, in a normal Windows 10 computer that is used daily is it safe to say the entry would be overwritten within 24 hrs after deletion?

No, sorry.
NTFS File Recovery - SleuthKitWiki

The answer you got from Jim @jimc is right, but there is one more thing: $J. The Journal shows the truth.

 
Posted : 02/12/2021 10:57 am
(@mscotgrove)
Posts: 938
Prominent Member
 

It is impossible to say how long an MFT entry marked as deleted will remain.  If for instance 1000s of files are deleted at one time, then it may be months before some entries are overwritten, if ever.

ie an entry may be overwritten on the next file create, or never.

Some disk defrag programs might purge unused MFT entries

 
Posted : 02/12/2021 1:31 pm
Share: