« Windows: simple web scraping with Wget.exe | Main | About base64 »

October 09, 2009

TrackBack

TrackBack URL for this entry:
http://www.typepad.com/services/trackback/6a00d83451c2f969e20120a6288a3c970c

Listed below are links to weblogs that reference Lab FTK Imager: file carving using the MFT :

Comments

Ken Pryor

Excellent post! I learned a lot from this. It's very timely for me, as I've been learning about NTFS and the MFT recently in a course I'm taking. Keep up the good work and thanks!
KP

Mark

You're welcome Ken ! Let me know if I can help you with other things regarding NTFS and MFT, Mark

troy

31h is not a marker for a cluster run. This number describes the cluster run, and can be other values than 31.

James

Thought I would expand on Troy's post. 31h is not a marker for the cluster run. However, if you go to offset 32(decimal)within the $DATA attribute and convert the two byte value, this will give you the decimal offset to the cluster run in decimal. So, in the above example the value at offset 32 is 0x40 00. Convert this (little endian of course) to decimal and you get 64. Go to byte 64 from the beginning of the $DATA attribute and you have the first part of the cluster run.

Hyip Monitor

Very nice article thanks for sharing this info.

Verify your Comment

Previewing your Comment

This is only a preview. Your comment has not yet been posted.

Working...
Your comment could not be posted. Error type:
Your comment has been saved. Comments are moderated and will not appear until approved by the author. Post another comment

The letters and numbers you entered did not match the image. Please try again.

As a final step before posting your comment, enter the letters and numbers you see in the image below. This prevents automated programs from posting comments.

Having trouble reading this image? View an alternate.

Working...

Post a comment

Comments are moderated, and will not appear until the author has approved them.