NTFS隐迹溯源

原名:analyzing-slack-space-and-file-system-artifacts

检查 NTFS 空闲空间、MFT 条目、USN 日志和备用数据流(ADS),以恢复隐藏或残留数据,重建已删除文件元数据,并从 USN 记录重构文件系统变更活动。在标准文件恢复不足时,用于 NTFS 镜像的深度取证分析,如查找 ADS 中隐藏的数据。

分类
学习研究
版本
v1.0
作者
弈韬(@ra1nzzz)
下载
0
收藏
0
发布
2026-08-18
更新
2026-08-19
TRACE 评分
3.4 / 5

内容概览

- When searching for hidden or residual data in file system slack space - For analyzing NTFS Master File Table (MFT) entries for deleted file metadata - When reconstructing file operations from the USN Change Journal - For detecting Alternate Data Streams (ADS) used to hide data or malware - During deep forensic analysis requiring examination beyond standard file recovery - Forensic disk image with NTFS file system - The Sleuth Kit (TSK) tools: istat, icat, fls, blkls, blkstat - MFTECmd (Eric Zimmerman) for MFT parsing - MFTExplorer for interactive MFT analysis - Understanding of NTFS structures (MFT, $UsnJrnl, $LogFile, ADS) - Python with analyzeMFT or mft library for automated parsing Concept Description --------- ------------- File slack Unused space between file end and cluster boundary containing residual data RAM slack Portion of slack from file end to sector boundary (historically…

查看 SKILL 详情