NTFS隐迹溯源
原名:analyzing-slack-space-and-file-system-artifacts
检查 NTFS 空闲空间、MFT 条目、USN 日志和备用数据流(ADS),以恢复隐藏或残留数据,重建已删除文件元数据,并从 USN 记录重构文件系统变更活动。在标准文件恢复不足时,用于 NTFS 镜像的深度取证分析,如查找 ADS 中隐藏的数据。
- 分类
- 学习研究
- 版本
- v1.0
- 作者
- 弈韬(@ra1nzzz)
- 下载
- 0
- 收藏
- 0
- 发布
- 2026-08-18
- 更新
- 2026-08-19
- TRACE 评分
- 3.4 / 5
内容概览
- When searching for hidden or residual data in file system slack space - For analyzing NTFS Master File Table (MFT) entries for deleted file metadata - When reconstructing file operations from the USN Change Journal - For detecting Alternate Data Streams (ADS) used to hide data or malware - During deep forensic analysis requiring examination beyond standard file recovery - Forensic disk image with NTFS file system - The Sleuth Kit (TSK) tools: istat, icat, fls, blkls, blkstat - MFTECmd (Eric Zimmerman) for MFT parsing - MFTExplorer for interactive MFT analysis - Understanding of NTFS structures (MFT, $UsnJrnl, $LogFile, ADS) - Python with analyzeMFT or mft library for automated parsing Concept Description --------- ------------- File slack Unused space between file end and cluster boundary containing residual data RAM slack Portion of slack from file end to sector boundary (historically…