Windows Forensics Cookbook
上QQ阅读APP看书,第一时间看更新

Windows File System Analysis

In this chapter, we will cover the following recipes:

  • NTFS analysis with The Sleuth Kit
  • Undeleting files from NTFS with Autopsy
  • Undeleting files from ReFS with ReclaiMe File Recovery
  • File carving with PhotoRec