Skip to main content

Examining NTFS File System

  • Chapter
  • First Online:

Abstract

The objectives of this chapter are to:

This is a preview of subscription content, log in via an institution.

Buying options

Chapter
USD   29.95
Price excludes VAT (USA)
  • Available as PDF
  • Read on any device
  • Instant download
  • Own it forever
eBook
USD   89.00
Price excludes VAT (USA)
  • Available as EPUB and PDF
  • Read on any device
  • Instant download
  • Own it forever
Hardcover Book
USD   119.99
Price excludes VAT (USA)
  • Durable hardcover edition
  • Dispatched in 3 to 5 business days
  • Free shipping worldwide - see info

Tax calculation will be finalised at checkout

Purchases are for personal use only

Learn about institutional subscriptions

References

  1. “New Technology File System (NTFS)”. http://www.pcguide.com/ref/hdd/file/ntfs/index.htm

  2. Brian Carrier. “File System Forensic Analysis”. Addison-Wesley Professional, 2005

    Google Scholar 

  3. The Structure and Function of an Operating System. http://www.sqa.org.uk/e-learning/COS101CD/page_18.htm

  4. http://homepage.cs.uri.edu/~thenry/csc487/video/62_MFT_Layout.pdf

  5. http://www.cse.scu.edu/~tschwarz/coen252_07Fall/Lectures/NTFS.html

  6. Petra Koruga, Miroslav Bača. Analysis of B-tree data structure and its usage in computer forensics. https://bib.irb.hr/datoteka/484192.B-tree.pdf

  7. Gyu-Sang Cho. NTFS Directory Index Analysis for Computer Forensics.

    Google Scholar 

  8. NTFS: Sometimes accurate file times are not in $FILE_NAME but in $STANDARD_INFORMATION. http://jnode.org/node/2861

  9. B-tree algorithms. http://www.semaphorecorp.com/btp/algo.html

  10. NTFS Basics. http://ntfs.com/ntfs_basics.htm

  11. https://technet.microsoft.com/en-us/library/cc781134(v=ws.10).aspx)

Download references

Author information

Authors and Affiliations

Authors

Rights and permissions

Reprints and permissions

Copyright information

© 2018 Springer Nature Switzerland AG

About this chapter

Check for updates. Verify currency and authenticity via CrossMark

Cite this chapter

Lin, X. (2018). Examining NTFS File System. In: Introductory Computer Forensics. Springer, Cham. https://doi.org/10.1007/978-3-030-00581-8_7

Download citation

  • DOI: https://doi.org/10.1007/978-3-030-00581-8_7

  • Published:

  • Publisher Name: Springer, Cham

  • Print ISBN: 978-3-030-00580-1

  • Online ISBN: 978-3-030-00581-8

  • eBook Packages: Computer ScienceComputer Science (R0)

Publish with us

Policies and ethics