Examining NTFS File System



The objectives of this chapter are to:


New Technology File System (NTFS) Master File Table (MFT) Encrypting File System (EFS) Property Allocation Sparse File 
These keywords were added by machine and not by the authors. This process is experimental and the keywords may be updated as the learning algorithm improves.


  1. 1.
    “New Technology File System (NTFS)”.
  2. 2.
    Brian Carrier. “File System Forensic Analysis”. Addison-Wesley Professional, 2005Google Scholar
  3. 3.
    The Structure and Function of an Operating System.
  4. 4.
  5. 5.
  6. 6.
    Petra Koruga, Miroslav Bača. Analysis of B-tree data structure and its usage in computer forensics.
  7. 7.
    Gyu-Sang Cho. NTFS Directory Index Analysis for Computer Forensics.Google Scholar
  8. 8.
    NTFS: Sometimes accurate file times are not in $FILE_NAME but in $STANDARD_INFORMATION.
  9. 9.
  10. 10.
  11. 11.

Copyright information

© Springer Nature Switzerland AG 2018

Authors and Affiliations

  1. 1.Department of Physics and Computer Science, Faculty of ScienceWilfrid Laurier UniversityWaterlooCanada

Personalised recommendations