Created: Thursday, 20 September 2018
Updated: Friday, 21 September 2018

The following scenario demonstrates a potentially confusing situation you might face as an investigator. Knowing extensively the NFTS internals will help you to reach at valid conclusions.

Assume that you have located a deleted suspicious file called showme.jpg.exe relevant to your case in a NTFS formatted volume. You go to its $MFT record entry, you verify that metadata match and entry flag is unallocated. However, surprisingly you discover that there is only one $DATA resident attribute with content having
[ZoneTransfer]

ZoneId=3

What are your next steps as an investigator?

ntfs $DATA ADS $MFT

© 2012 - 2023 Armen Arsakian updated atThursday 07 November 2019Contact: contact at arsakian.com

-2094 . 4041