Академический Документы
Профессиональный Документы
Культура Документы
Livia Nguyen
CFR105
Date Created:
UTC: 2/1/2012 11:44:23 PM
Local: 2/1/2012 4:44:23 PM
Filename Attribute
Duhr.txt
File Record Header
Date Created:
UTC: 2/1/2012 11:44:24 PM
Local: 2/1/2012 4:44:24 PM
Filename Attribute
Start Cluster:
Hex: 26 B0 04 = 4B026
Dec: 307,238
NTFS FILE STRUCTURE 6
Grumium.txt
File Record Header
Date Created:
UTC: 2/2/2012 12:20:16 AM
Local: 2/1/2012 5:20:16 PM
Filename Attribute
Start Cluster:
Hex: 81 96 04 = 49681
Dec: 300,673
NTFS FILE STRUCTURE 8
31 3 represent the starting offset number and 1 represent the number of contiguous clusters in
the run list.
Fragment 2
31 3 represent the starting offset number and 1 represent the number of contiguous clusters in
the run list.
Duhr.txt
Fragment 1
31 3 represent the starting offset number and 1 represent the number of contiguous clusters in
the run list.
NTFS FILE STRUCTURE 10
Fragment 2
11 1 represent the starting offset number and 1 represent the number of contiguous clusters in
the run list.
Grumium.txt
31 3 represent the starting offset number and 1 represent the number of contiguous clusters in
the run list.
Click Save Selection and save it as Grumium.txt because there are no other fragment and this is
the whole file.
Result:
Merged file fragment into one file using command prompt copy/b command.
NTFS FILE STRUCTURE 13
NTFS FILE STRUCTURE 14
Verified File:
After merging the file fragment into one, I verified the file size to make sure that it is exact same
size as the file size number appear in the $MFT file.
NTFS FILE STRUCTURE 15
NTFS FILE STRUCTURE 16
Reference
Carrier, B. (2011). File System Forensic Analysis. Upper Saddle River, NJ: Addison-Wesley.
ntfs/ntfs/attributes/index.html