SavitarX
search
⌘Ctrlk
LinkedinTryHackme
SavitarX
  • README
  • CERTIFICATIONS & notes
    • My Roadmap to Becoming a Penetration Tester & Red Team
    • Comp Network
    • Red Team
    • Blue Team
      • CDSA
      • DFIR
        • Introduction to Digital Forensics
        • Investigating Windows Endpoints
          • Windows Event Logs
          • The Registry
          • Evidence of Execution
          • Persistence and Lateral Movement
          • Anatomy of NTFS
            • Metafiles, MFT, Journaling, ADS
            • MACB Timestamps
            • Parsing the MFT and USN Journal
          • File Deletion and Recovery
          • LNK Files and Jump Lists
          • User Behavior Forensics
        • Investigating Windows Memory
        • Investigating Linux Devices
        • MacOS Forensics
    • Web Pentesting
  • Writeups
    • Tryhackme
    • HTB Sherlocks
  • Machines to pratice for
    • CPTS Preparation
    • CDSA Preparation
    • OSEP
  • The Computer Science and Engineering program
    • Read this
    • Computer Science
    • Security
gitbookPowered by GitBook
block-quoteOn this pagechevron-down
  1. CERTIFICATIONS & noteschevron-right
  2. Blue Teamchevron-right
  3. DFIRchevron-right
  4. Investigating Windows Endpoints

Anatomy of NTFS

Metafiles, MFT, Journaling, ADSchevron-rightMACB Timestampschevron-rightParsing the MFT and USN Journalchevron-right
PreviousSMB, RDP, WMI, PsExec & UALchevron-leftNextMetafiles, MFT, Journaling, ADSchevron-right