SlideShare a Scribd company logo
IDEA Objective: Gaining Factual Knowledge
(Terminology, Classification, Methods, Trends)
IDEA Objective: Learning to apply course materials
(to improve thinking, problem solving, and decisions)
 NTFS offers what FAT does not:
› Performance
› Reliability
› Compatibility
› Provides more information and control about/on a file
 NTFS was Microsoft’s move toward a journaling
file system
 It was designed to quickly perform standard file
operations as:
› Reading
› Writing
› Searching
› ...and File system recovery on very large hard disks
 FAT will still exist in mobile and small storage
devices, but NTFS more likely for Windows
 NTFS is more complex and more scalable
 FAT retrieves a file by searching the chain of
allocation units directory entries, NTFS finds
files more directly
 Less Slack Space!
 Designed by Microsoft and is the default file
system for:
› Windows NT
› Windows XP, Vista, 7, 8, 10, and 11
 The first information on the volume is the
Partition Boot Sector which starts at Sector 0
and can be up to 16 sectors long
 The first file on an NTFS volume is a Master
File Table (MFT)
› The MFT holds information about all files and
folders on the volume
Partition
Boot Sector
Master File Table File Area
Boot Sector: gives the starting location of the MFT, cluster size, size of each
MFT entry (usually 1024 bytes)
Master File Table: is basically a relational database table in which
information (attributes) for each file or directory is represented by a record in
the MFT. There are also System Files used by file system to store metadata
and implement the file system
 In the NTFS MFT
› All files and folders are stored in separate
records of 1024 bytes each
 Each record contains file or folder
information
› This information is divided into record fields
containing metadata
 A record field is referred to as an attribute
ID
 When a file is deleted:
› The name is removed from the parent directory index
› The MFT entry is unallocated
› Clusters are unallocated
 Problem: when filename is removed from parent
directory, the index is resorted and name information
could be lost
› However, MFT entries are found in one table, so all unallocated
entries can be found
› And each entry has the $FILE_NAME attribute with the file
reference address of the parent directory, so when an
unallocated entry is found, its entire path can be determined
 To recover all deleted files in NTFS, examine MFT for
unallocated entries and determine name using
$FILE_NAME attribute and parent directory file
reference
 Alternate Data streams
› Ways data can be appended to existing files
› Can obscure valuable evidentiary data, intentionally
or by coincidence
 In NTFS, a data stream becomes an additional
file attribute
› Allows the file to be associated with different
applications
 You can only tell whether a file has a data
stream attached by examining that file’s MFT
entry

More Related Content

Similar to NTFS Forensics.pptx

Alternate Data Streams
Alternate Data StreamsAlternate Data Streams
Alternate Data Streams
nephijohnson
 
Windows file system
Windows file systemWindows file system
Windows file system
sumitjain2013
 
Os
OsOs
How to convert file system without data loss
How to convert file system without data lossHow to convert file system without data loss
How to convert file system without data loss
Lisa Liao
 
File system, dual boot, addon components, create user
File system, dual boot, addon components, create userFile system, dual boot, addon components, create user
File system, dual boot, addon components, create user
Harman Gahir
 
File System, Dual Boot, Addon Components, Create User
File System, Dual Boot, Addon Components, Create UserFile System, Dual Boot, Addon Components, Create User
File System, Dual Boot, Addon Components, Create User
Harman Gahir
 
File System
File SystemFile System
File System
Thayalan Danusan
 
NTFS file system
NTFS file systemNTFS file system
NTFS file system
Ravi Yasas
 
Ntfs forensics
Ntfs forensicsNtfs forensics
chapter10 - File structures.pdf
chapter10 - File structures.pdfchapter10 - File structures.pdf
chapter10 - File structures.pdf
satonaka3
 
Fat File Systems
Fat File SystemsFat File Systems
Fat File Systems
ArthyR3
 
File System and File allocation tables
File System and File allocation tablesFile System and File allocation tables
File System and File allocation tables
shashikant pabari
 
NTFS
NTFSNTFS
NTFS
ArthyR3
 
File system
File systemFile system
File system
Mohammad Noman
 
Guide to Windows 7 - Managing File Systems
Guide to Windows 7 - Managing File SystemsGuide to Windows 7 - Managing File Systems
Guide to Windows 7 - Managing File Systems
Gene Carboni
 
NTFS.ppt
NTFS.pptNTFS.ppt
NTFS.ppt
jlmansilla
 
Ntfs and computer forensics
Ntfs and computer forensicsNtfs and computer forensics
Ntfs and computer forensics
Gaurav Ragtah
 
File system
File systemFile system
File system
Didar Hussain
 
9781111306366 ppt ch4
9781111306366 ppt ch49781111306366 ppt ch4
9781111306366 ppt ch4
Dr. Ahmed Al Zaidy
 
Storage Mediums and Fragmentation
Storage Mediums and FragmentationStorage Mediums and Fragmentation
Storage Mediums and Fragmentation
Jonathan Reid
 

Similar to NTFS Forensics.pptx (20)

Alternate Data Streams
Alternate Data StreamsAlternate Data Streams
Alternate Data Streams
 
Windows file system
Windows file systemWindows file system
Windows file system
 
Os
OsOs
Os
 
How to convert file system without data loss
How to convert file system without data lossHow to convert file system without data loss
How to convert file system without data loss
 
File system, dual boot, addon components, create user
File system, dual boot, addon components, create userFile system, dual boot, addon components, create user
File system, dual boot, addon components, create user
 
File System, Dual Boot, Addon Components, Create User
File System, Dual Boot, Addon Components, Create UserFile System, Dual Boot, Addon Components, Create User
File System, Dual Boot, Addon Components, Create User
 
File System
File SystemFile System
File System
 
NTFS file system
NTFS file systemNTFS file system
NTFS file system
 
Ntfs forensics
Ntfs forensicsNtfs forensics
Ntfs forensics
 
chapter10 - File structures.pdf
chapter10 - File structures.pdfchapter10 - File structures.pdf
chapter10 - File structures.pdf
 
Fat File Systems
Fat File SystemsFat File Systems
Fat File Systems
 
File System and File allocation tables
File System and File allocation tablesFile System and File allocation tables
File System and File allocation tables
 
NTFS
NTFSNTFS
NTFS
 
File system
File systemFile system
File system
 
Guide to Windows 7 - Managing File Systems
Guide to Windows 7 - Managing File SystemsGuide to Windows 7 - Managing File Systems
Guide to Windows 7 - Managing File Systems
 
NTFS.ppt
NTFS.pptNTFS.ppt
NTFS.ppt
 
Ntfs and computer forensics
Ntfs and computer forensicsNtfs and computer forensics
Ntfs and computer forensics
 
File system
File systemFile system
File system
 
9781111306366 ppt ch4
9781111306366 ppt ch49781111306366 ppt ch4
9781111306366 ppt ch4
 
Storage Mediums and Fragmentation
Storage Mediums and FragmentationStorage Mediums and Fragmentation
Storage Mediums and Fragmentation
 

Recently uploaded

Everything you wanted to know about LIHTC
Everything you wanted to know about LIHTCEverything you wanted to know about LIHTC
Everything you wanted to know about LIHTC
Roger Valdez
 
Intelligence supported media monitoring in veterinary medicine
Intelligence supported media monitoring in veterinary medicineIntelligence supported media monitoring in veterinary medicine
Intelligence supported media monitoring in veterinary medicine
AndrzejJarynowski
 
Analysis insight about a Flyball dog competition team's performance
Analysis insight about a Flyball dog competition team's performanceAnalysis insight about a Flyball dog competition team's performance
Analysis insight about a Flyball dog competition team's performance
roli9797
 
一比一原版(Dalhousie毕业证书)达尔豪斯大学毕业证如何办理
一比一原版(Dalhousie毕业证书)达尔豪斯大学毕业证如何办理一比一原版(Dalhousie毕业证书)达尔豪斯大学毕业证如何办理
一比一原版(Dalhousie毕业证书)达尔豪斯大学毕业证如何办理
mzpolocfi
 
The Ipsos - AI - Monitor 2024 Report.pdf
The  Ipsos - AI - Monitor 2024 Report.pdfThe  Ipsos - AI - Monitor 2024 Report.pdf
The Ipsos - AI - Monitor 2024 Report.pdf
Social Samosa
 
Global Situational Awareness of A.I. and where its headed
Global Situational Awareness of A.I. and where its headedGlobal Situational Awareness of A.I. and where its headed
Global Situational Awareness of A.I. and where its headed
vikram sood
 
Natural Language Processing (NLP), RAG and its applications .pptx
Natural Language Processing (NLP), RAG and its applications .pptxNatural Language Processing (NLP), RAG and its applications .pptx
Natural Language Processing (NLP), RAG and its applications .pptx
fkyes25
 
Learn SQL from basic queries to Advance queries
Learn SQL from basic queries to Advance queriesLearn SQL from basic queries to Advance queries
Learn SQL from basic queries to Advance queries
manishkhaire30
 
一比一原版(Harvard毕业证书)哈佛大学毕业证如何办理
一比一原版(Harvard毕业证书)哈佛大学毕业证如何办理一比一原版(Harvard毕业证书)哈佛大学毕业证如何办理
一比一原版(Harvard毕业证书)哈佛大学毕业证如何办理
zsjl4mimo
 
一比一原版(UMN文凭证书)明尼苏达大学毕业证如何办理
一比一原版(UMN文凭证书)明尼苏达大学毕业证如何办理一比一原版(UMN文凭证书)明尼苏达大学毕业证如何办理
一比一原版(UMN文凭证书)明尼苏达大学毕业证如何办理
nyfuhyz
 
一比一原版(Adelaide毕业证书)阿德莱德大学毕业证如何办理
一比一原版(Adelaide毕业证书)阿德莱德大学毕业证如何办理一比一原版(Adelaide毕业证书)阿德莱德大学毕业证如何办理
一比一原版(Adelaide毕业证书)阿德莱德大学毕业证如何办理
slg6lamcq
 
原版制作(Deakin毕业证书)迪肯大学毕业证学位证一模一样
原版制作(Deakin毕业证书)迪肯大学毕业证学位证一模一样原版制作(Deakin毕业证书)迪肯大学毕业证学位证一模一样
原版制作(Deakin毕业证书)迪肯大学毕业证学位证一模一样
u86oixdj
 
办(uts毕业证书)悉尼科技大学毕业证学历证书原版一模一样
办(uts毕业证书)悉尼科技大学毕业证学历证书原版一模一样办(uts毕业证书)悉尼科技大学毕业证学历证书原版一模一样
办(uts毕业证书)悉尼科技大学毕业证学历证书原版一模一样
apvysm8
 
University of New South Wales degree offer diploma Transcript
University of New South Wales degree offer diploma TranscriptUniversity of New South Wales degree offer diploma Transcript
University of New South Wales degree offer diploma Transcript
soxrziqu
 
一比一原版(Glasgow毕业证书)格拉斯哥大学毕业证如何办理
一比一原版(Glasgow毕业证书)格拉斯哥大学毕业证如何办理一比一原版(Glasgow毕业证书)格拉斯哥大学毕业证如何办理
一比一原版(Glasgow毕业证书)格拉斯哥大学毕业证如何办理
g4dpvqap0
 
一比一原版(Chester毕业证书)切斯特大学毕业证如何办理
一比一原版(Chester毕业证书)切斯特大学毕业证如何办理一比一原版(Chester毕业证书)切斯特大学毕业证如何办理
一比一原版(Chester毕业证书)切斯特大学毕业证如何办理
74nqk8xf
 
06-04-2024 - NYC Tech Week - Discussion on Vector Databases, Unstructured Dat...
06-04-2024 - NYC Tech Week - Discussion on Vector Databases, Unstructured Dat...06-04-2024 - NYC Tech Week - Discussion on Vector Databases, Unstructured Dat...
06-04-2024 - NYC Tech Week - Discussion on Vector Databases, Unstructured Dat...
Timothy Spann
 
My burning issue is homelessness K.C.M.O.
My burning issue is homelessness K.C.M.O.My burning issue is homelessness K.C.M.O.
My burning issue is homelessness K.C.M.O.
rwarrenll
 
State of Artificial intelligence Report 2023
State of Artificial intelligence Report 2023State of Artificial intelligence Report 2023
State of Artificial intelligence Report 2023
kuntobimo2016
 
一比一原版(GWU,GW文凭证书)乔治·华盛顿大学毕业证如何办理
一比一原版(GWU,GW文凭证书)乔治·华盛顿大学毕业证如何办理一比一原版(GWU,GW文凭证书)乔治·华盛顿大学毕业证如何办理
一比一原版(GWU,GW文凭证书)乔治·华盛顿大学毕业证如何办理
bopyb
 

Recently uploaded (20)

Everything you wanted to know about LIHTC
Everything you wanted to know about LIHTCEverything you wanted to know about LIHTC
Everything you wanted to know about LIHTC
 
Intelligence supported media monitoring in veterinary medicine
Intelligence supported media monitoring in veterinary medicineIntelligence supported media monitoring in veterinary medicine
Intelligence supported media monitoring in veterinary medicine
 
Analysis insight about a Flyball dog competition team's performance
Analysis insight about a Flyball dog competition team's performanceAnalysis insight about a Flyball dog competition team's performance
Analysis insight about a Flyball dog competition team's performance
 
一比一原版(Dalhousie毕业证书)达尔豪斯大学毕业证如何办理
一比一原版(Dalhousie毕业证书)达尔豪斯大学毕业证如何办理一比一原版(Dalhousie毕业证书)达尔豪斯大学毕业证如何办理
一比一原版(Dalhousie毕业证书)达尔豪斯大学毕业证如何办理
 
The Ipsos - AI - Monitor 2024 Report.pdf
The  Ipsos - AI - Monitor 2024 Report.pdfThe  Ipsos - AI - Monitor 2024 Report.pdf
The Ipsos - AI - Monitor 2024 Report.pdf
 
Global Situational Awareness of A.I. and where its headed
Global Situational Awareness of A.I. and where its headedGlobal Situational Awareness of A.I. and where its headed
Global Situational Awareness of A.I. and where its headed
 
Natural Language Processing (NLP), RAG and its applications .pptx
Natural Language Processing (NLP), RAG and its applications .pptxNatural Language Processing (NLP), RAG and its applications .pptx
Natural Language Processing (NLP), RAG and its applications .pptx
 
Learn SQL from basic queries to Advance queries
Learn SQL from basic queries to Advance queriesLearn SQL from basic queries to Advance queries
Learn SQL from basic queries to Advance queries
 
一比一原版(Harvard毕业证书)哈佛大学毕业证如何办理
一比一原版(Harvard毕业证书)哈佛大学毕业证如何办理一比一原版(Harvard毕业证书)哈佛大学毕业证如何办理
一比一原版(Harvard毕业证书)哈佛大学毕业证如何办理
 
一比一原版(UMN文凭证书)明尼苏达大学毕业证如何办理
一比一原版(UMN文凭证书)明尼苏达大学毕业证如何办理一比一原版(UMN文凭证书)明尼苏达大学毕业证如何办理
一比一原版(UMN文凭证书)明尼苏达大学毕业证如何办理
 
一比一原版(Adelaide毕业证书)阿德莱德大学毕业证如何办理
一比一原版(Adelaide毕业证书)阿德莱德大学毕业证如何办理一比一原版(Adelaide毕业证书)阿德莱德大学毕业证如何办理
一比一原版(Adelaide毕业证书)阿德莱德大学毕业证如何办理
 
原版制作(Deakin毕业证书)迪肯大学毕业证学位证一模一样
原版制作(Deakin毕业证书)迪肯大学毕业证学位证一模一样原版制作(Deakin毕业证书)迪肯大学毕业证学位证一模一样
原版制作(Deakin毕业证书)迪肯大学毕业证学位证一模一样
 
办(uts毕业证书)悉尼科技大学毕业证学历证书原版一模一样
办(uts毕业证书)悉尼科技大学毕业证学历证书原版一模一样办(uts毕业证书)悉尼科技大学毕业证学历证书原版一模一样
办(uts毕业证书)悉尼科技大学毕业证学历证书原版一模一样
 
University of New South Wales degree offer diploma Transcript
University of New South Wales degree offer diploma TranscriptUniversity of New South Wales degree offer diploma Transcript
University of New South Wales degree offer diploma Transcript
 
一比一原版(Glasgow毕业证书)格拉斯哥大学毕业证如何办理
一比一原版(Glasgow毕业证书)格拉斯哥大学毕业证如何办理一比一原版(Glasgow毕业证书)格拉斯哥大学毕业证如何办理
一比一原版(Glasgow毕业证书)格拉斯哥大学毕业证如何办理
 
一比一原版(Chester毕业证书)切斯特大学毕业证如何办理
一比一原版(Chester毕业证书)切斯特大学毕业证如何办理一比一原版(Chester毕业证书)切斯特大学毕业证如何办理
一比一原版(Chester毕业证书)切斯特大学毕业证如何办理
 
06-04-2024 - NYC Tech Week - Discussion on Vector Databases, Unstructured Dat...
06-04-2024 - NYC Tech Week - Discussion on Vector Databases, Unstructured Dat...06-04-2024 - NYC Tech Week - Discussion on Vector Databases, Unstructured Dat...
06-04-2024 - NYC Tech Week - Discussion on Vector Databases, Unstructured Dat...
 
My burning issue is homelessness K.C.M.O.
My burning issue is homelessness K.C.M.O.My burning issue is homelessness K.C.M.O.
My burning issue is homelessness K.C.M.O.
 
State of Artificial intelligence Report 2023
State of Artificial intelligence Report 2023State of Artificial intelligence Report 2023
State of Artificial intelligence Report 2023
 
一比一原版(GWU,GW文凭证书)乔治·华盛顿大学毕业证如何办理
一比一原版(GWU,GW文凭证书)乔治·华盛顿大学毕业证如何办理一比一原版(GWU,GW文凭证书)乔治·华盛顿大学毕业证如何办理
一比一原版(GWU,GW文凭证书)乔治·华盛顿大学毕业证如何办理
 

NTFS Forensics.pptx

  • 1.
  • 2. IDEA Objective: Gaining Factual Knowledge (Terminology, Classification, Methods, Trends) IDEA Objective: Learning to apply course materials (to improve thinking, problem solving, and decisions)
  • 3.  NTFS offers what FAT does not: › Performance › Reliability › Compatibility › Provides more information and control about/on a file  NTFS was Microsoft’s move toward a journaling file system  It was designed to quickly perform standard file operations as: › Reading › Writing › Searching › ...and File system recovery on very large hard disks
  • 4.  FAT will still exist in mobile and small storage devices, but NTFS more likely for Windows  NTFS is more complex and more scalable  FAT retrieves a file by searching the chain of allocation units directory entries, NTFS finds files more directly  Less Slack Space!
  • 5.  Designed by Microsoft and is the default file system for: › Windows NT › Windows XP, Vista, 7, 8, 10, and 11
  • 6.  The first information on the volume is the Partition Boot Sector which starts at Sector 0 and can be up to 16 sectors long  The first file on an NTFS volume is a Master File Table (MFT) › The MFT holds information about all files and folders on the volume
  • 7. Partition Boot Sector Master File Table File Area Boot Sector: gives the starting location of the MFT, cluster size, size of each MFT entry (usually 1024 bytes) Master File Table: is basically a relational database table in which information (attributes) for each file or directory is represented by a record in the MFT. There are also System Files used by file system to store metadata and implement the file system
  • 8.
  • 9.
  • 10.  In the NTFS MFT › All files and folders are stored in separate records of 1024 bytes each  Each record contains file or folder information › This information is divided into record fields containing metadata  A record field is referred to as an attribute ID
  • 11.
  • 12.  When a file is deleted: › The name is removed from the parent directory index › The MFT entry is unallocated › Clusters are unallocated  Problem: when filename is removed from parent directory, the index is resorted and name information could be lost › However, MFT entries are found in one table, so all unallocated entries can be found › And each entry has the $FILE_NAME attribute with the file reference address of the parent directory, so when an unallocated entry is found, its entire path can be determined  To recover all deleted files in NTFS, examine MFT for unallocated entries and determine name using $FILE_NAME attribute and parent directory file reference
  • 13.  Alternate Data streams › Ways data can be appended to existing files › Can obscure valuable evidentiary data, intentionally or by coincidence  In NTFS, a data stream becomes an additional file attribute › Allows the file to be associated with different applications  You can only tell whether a file has a data stream attached by examining that file’s MFT entry