ObjID added to an M...
 
Notifications
Clear all

ObjID added to an MFT record

5 Posts
3 Users
0 Reactions
790 Views
PaulSanderson
(@paulsanderson)
Honorable Member
Joined: 20 years ago
Posts: 651
Topic starter   [#7997]

I am looking at some MFT records in VSC's that have different MFT
modified dates. The only difference between the MFT records is that
current version of the MFT record has an objID stream and the older
entries (the ones in the VSC's) do not.

Does anyone have any ideas as to why/when an objID might be added to
an MFT entry?



   
Quote
joakims
(@joakims)
Estimable Member
Joined: 16 years ago
Posts: 224
 

I've wondered about this myself. Found some links suggesting it has to do with Distributed Link Tracking..

Besides that, I have a comprehensive mft2csv app I'm working on and by inspecting the log, I notice that all files on my system with ObjectID set, has file permissions set to archive. I currently don't know what it means, but is what I've just found.



   
ReplyQuote
joakims
(@joakims)
Estimable Member
Joined: 16 years ago
Posts: 224
 

http//msdn.microsoft.com/en-us/library/aa363997(v=vs.85).aspx



   
ReplyQuote
PaulSanderson
(@paulsanderson)
Honorable Member
Joined: 20 years ago
Posts: 651
Topic starter  

Thanks Joackim - I am aware of that (this information was included in my program LinkAlyzer a long time ago - www.sandersonforensics.com/linkalyzer.html)

I am looking at reasons that an ObjID might be added to an MFT entry - creation of a link file is one, are there others?



   
ReplyQuote
(@j2222)
Eminent Member
Joined: 21 years ago
Posts: 36
 

How about the system indexer?



   
ReplyQuote
Share: