官术网_书友最值得收藏!

  • Windows Forensics Cookbook
  • Oleg Skulkin Scar de Courcier
  • 270字
  • 2021-07-02 20:57:37

Windows file system

Windows machines use NTFS, which used to stand for New Technology filesystem, although the acronym has now become obsolete. All versions of Windows run on NTFS as default.

The main thing to remember about NTFS is that everything is a file. The idea behind the filesystems creation was that it would be easily scalable, as well as being secure and reliable at all levels. This does present some unique challenges for forensic investigation and administrative usage, however knowing that any file can be located anywhere on the system makes it challenging to understand precisely what one is looking at when analyzing a machine.

The Master File Table (MFT) is the basis of the filesystem. In here, we find all the relevant information concerning files. It is worth noting that the first entry in the MFT is an entry that refers to the MFT itself, which can confuse people who are new to Windows filesystem analysis.

One of the most important elements in Windows investigations is the registry, where keys containing information regarding the configuration of the system, along with other forensic gems are stored. Tools such as RegEdit and RegRipper can be very useful in registry analysis, as can many of the more widely used general forensic programs, such as EnCase and BlackLight.

We will discuss the specifics of various investigative elements within the Windows NT filesystem throughout the book. For the moment, the most pertinent points to remember are that everything in NTFS is a file; that the master file table forms the base of the filesystem; and that the registry contains useful system configuration information.

主站蜘蛛池模板: 肥东县| 广丰县| 饶平县| 丽水市| 化隆| 大埔县| 抚远县| 新野县| 调兵山市| 湖南省| 易门县| 延庆县| 泗洪县| 晋宁县| 蚌埠市| 湘潭县| 宣威市| 乌苏市| 龙江县| 青岛市| 潮安县| 宜川县| 荆州市| 略阳县| 手游| 万荣县| 巴彦淖尔市| 合川市| 淮安市| 北安市| 军事| 喀喇沁旗| 交口县| 汉中市| 旺苍县| 广饶县| 买车| 大冶市| 嘉义县| 荣昌县| 永新县|