90 likes | 118 Views
COEN 252 Computer Forensics. Master Boot Record NTFS Example. NTFS Example. Use WinHex to go directly to the partition. WinHex will read the boot sector and allow easier navigation. NTFS Example. Disassembling MFT entries by hand is difficult. Use tools.
E N D
COEN 252 Computer Forensics Master Boot Record NTFS Example
NTFS Example • Use WinHex to go directly to the partition. • WinHex will read the boot sector and allow easier navigation.
NTFS Example • Disassembling MFT entries by hand is difficult. • Use tools. • WinHex allows you to look at the file structure.
NTFS Example • WinHex allows to search for strings
NTFS Example • But string searches can take a long time.