-
Notifications
You must be signed in to change notification settings - Fork 3
Open
Description
Playing with your $I30 parsing in MFTECMD.
From my understanding, would it be a stretch to add a full path or parent path column and provide the MFT like you have with the $J?
Also - since the timestamp is the FILENAME timestamp, can you align the headers with the MFT parsed output from MFTECMD?
Playing with Bulk Extractor-Rec and it pulls out $i30 attributes into a file. MFTECMD worked really well to stitch it all back together. Ran this over an encrypted VHDX and will do a comparison with running Joachim Schictts tools
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels