@port139 Blog

基本的にはデジタル・フォレンジックの技術について取り扱っていますが、記載内容には高確率で誤りが含まれる可能性があります。

MFT Entry Number:31-128-3

MFTレコードの内容を確認

Pointed to by file:
F://note.exe
F://NOTEPAD.EXE
F:/test/noteB.txt
File Type:
MS-DOS executable (EXE), OS/2 or MS Windows
MD5 of content:
518cfcf8e0c7b133d365ddaa22916052
SHA-1 of content:
8aa33633f4abcd071782a5ce502684486ad3e314
Details:
MFT Entry Header Values:
Entry: 31 Sequence: 6
$LogFile Sequence Number: 1271184
Allocated File
Links: 3

$STANDARD_INFORMATION Attribute Values:
Flags: Archive
Owner ID: 0 Security ID: 268
Created: Sat Sep 10 22:12:18 2005
File Modified: Thu Apr 3 21:00:00 2003
MFT Modified: Sat Sep 10 22:35:56 2005
Accessed: Sat Sep 10 22:12:18 2005

$FILE_NAME Attribute Values:
Flags: Archive
Name: note.exe, NOTEPAD.EXE, noteB.txt
Parent MFT Entry: 5 Sequence: 5
Allocated Size: 0 Actual Size: 0
Created: Sat Sep 10 22:12:18 2005
File Modified: Sat Sep 10 22:12:18 2005
MFT Modified: Sat Sep 10 22:12:18 2005
Accessed: Sat Sep 10 22:12:18 2005

Attributes:
$STANDARD_INFORMATION (16-0) Name: N/A Resident size: 72
$FILE_NAME (48-4) Name: N/A Resident size: 82
$FILE_NAME (48-2) Name: N/A Resident size: 88
$FILE_NAME (48-5) Name: N/A Resident size: 84
$DATA (128-3) Name: $Data Non-Resident size: 66048
88908 88909 88910 88911 88912 88913 88914 88915
88916 88917 88918 88919 88920 88921 88922 88923
88924 88925 88926 88927 88928 88929 88930 88931
88932 88933 88934 88935 88936 88937 88938 88939
88940 88941 88942 88943 88944 88945 88946 88947
88948 88949 88950 88951 88952 88953 88954 88955
88956 88957 88958 88959 88960 88961 88962 88963
88964 88965 88966 88967 88968 88969 88970 88971
88972 88973 88974 88975 88976 88977 88978 88979
88980 88981 88982 88983 88984 88985 88986 88987
88988 88989 88990 88991 88992 88993 88994 88995
88996 88997 88998 88999 89000 89001 89002 89003
89004 89005 89006 89007 89008 89009 89010 89011
89012 89013 89014 89015 89016 89017 89018 89019
89020 89021 89022 89023 89024 89025 89026 89027
89028 89029 89030 89031 89032 89033 89034 89035
89036