官术网_书友最值得收藏!

  • Windows Forensics Cookbook
  • Oleg Skulkin Scar de Courcier
  • 270字
  • 2021-07-02 20:57:37

Windows file system

Windows machines use NTFS, which used to stand for New Technology filesystem, although the acronym has now become obsolete. All versions of Windows run on NTFS as default.

The main thing to remember about NTFS is that everything is a file. The idea behind the filesystems creation was that it would be easily scalable, as well as being secure and reliable at all levels. This does present some unique challenges for forensic investigation and administrative usage, however knowing that any file can be located anywhere on the system makes it challenging to understand precisely what one is looking at when analyzing a machine.

The Master File Table (MFT) is the basis of the filesystem. In here, we find all the relevant information concerning files. It is worth noting that the first entry in the MFT is an entry that refers to the MFT itself, which can confuse people who are new to Windows filesystem analysis.

One of the most important elements in Windows investigations is the registry, where keys containing information regarding the configuration of the system, along with other forensic gems are stored. Tools such as RegEdit and RegRipper can be very useful in registry analysis, as can many of the more widely used general forensic programs, such as EnCase and BlackLight.

We will discuss the specifics of various investigative elements within the Windows NT filesystem throughout the book. For the moment, the most pertinent points to remember are that everything in NTFS is a file; that the master file table forms the base of the filesystem; and that the registry contains useful system configuration information.

主站蜘蛛池模板: 安仁县| 进贤县| 临洮县| 乌鲁木齐县| 大洼县| 龙陵县| 胶州市| 高碑店市| 沙田区| 瑞金市| 东乡族自治县| 米泉市| 靖西县| 怀仁县| 商丘市| 肃南| 马公市| 巨野县| 尼木县| 锡林浩特市| 杭锦后旗| 湾仔区| 大石桥市| 宁津县| 楚雄市| 丹凤县| 五寨县| 黑龙江省| 开封县| 长泰县| 广安市| 稻城县| 阿荣旗| 凤城市| 和硕县| 兖州市| 沅陵县| 绥阳县| 息烽县| 望江县| 成武县|