EricZimmerman / EricZimmerman/Issues
MFTECMD - $I30 parsing full paths
Open
- Dominant language
- No language data
- Stars
- 14
- Forks
- 3
- PR merge metrics
- No merged PRs in 30d
Description
Playing with your $I30 parsing in MFTECMD.
From my understanding, would it be a stretch to add a full path or parent path column and provide the MFT like you have with the $J?
Also - since the timestamp is the FILENAME timestamp, can you align the headers with the MFT parsed output from MFTECMD?
Playing with Bulk Extractor-Rec and it pulls out $i30 attributes into a file. MFTECMD worked really well to stitch it all back together. Ran this over an encrypted VHDX and will do a comparison with running Joachim Schictts tools
Contributor guide
No contributing guide indexed for this repository
Assessment
This issue has not been assessed yet.