官术网_书友最值得收藏!

Windows file system

Windows machines use NTFS, which used to stand for New Technology filesystem, although the acronym has now become obsolete. All versions of Windows run on NTFS as default.

The main thing to remember about NTFS is that everything is a file. The idea behind the filesystems creation was that it would be easily scalable, as well as being secure and reliable at all levels. This does present some unique challenges for forensic investigation and administrative usage, however knowing that any file can be located anywhere on the system makes it challenging to understand precisely what one is looking at when analyzing a machine.

The Master File Table (MFT) is the basis of the filesystem. In here, we find all the relevant information concerning files. It is worth noting that the first entry in the MFT is an entry that refers to the MFT itself, which can confuse people who are new to Windows filesystem analysis.

One of the most important elements in Windows investigations is the registry, where keys containing information regarding the configuration of the system, along with other forensic gems are stored. Tools such as RegEdit and RegRipper can be very useful in registry analysis, as can many of the more widely used general forensic programs, such as EnCase and BlackLight.

We will discuss the specifics of various investigative elements within the Windows NT filesystem throughout the book. For the moment, the most pertinent points to remember are that everything in NTFS is a file; that the master file table forms the base of the filesystem; and that the registry contains useful system configuration information.

主站蜘蛛池模板: 梧州市| 黄龙县| 泸溪县| 巢湖市| 平顺县| 若尔盖县| 乡城县| 宁南县| 南澳县| 循化| 新乐市| 嵊泗县| 元氏县| 青田县| 广元市| 白城市| 达州市| 大安市| 安远县| 郑州市| 道孚县| 淳化县| 乌兰察布市| 保亭| 即墨市| 琼中| 临武县| 祥云县| 北川| 平泉县| 张家港市| 华蓥市| 肇庆市| 错那县| 麻阳| 屯门区| 乌拉特前旗| 封丘县| 商河县| 吉林省| 揭西县|