AboutDFIR.com – The Definitive Compendium Project
Digital Forensics & Incident Response

File Systems

File Systems Artifacts

File SystemArtifactResource Link
FAT32File CarvingFAT32 File Carving
HFS+MacOS File Movements
HFS+HFS+ Overview
NTFS$I30 Files13Cubed - Windows NTFS Index Attributes ($I30 Files)
NTFS$JUSN Journal: Where have you been all my life
NTFS$JThe Windows USN Journal
NTFS$JCarving $USN journal entries
NTFS$J13Cubed - NTFS Journal Forensics
NTFS$JInvestigating USN Journal - Forensafe
NTFS$MFTParsing the $MFT NTFS metadata file
NTFS$MFTResolving File Paths Using The MFT - RAT in Mi Kitchen
NTFSAlternate Data Streams[CQURElabs] Alternate Data Streams
NTFSAlternate Data StreamsAlternate Data Streams (ADS)
NTFSMACB Timestamps13Cubed - Windows MACB Timestamps (NTFS Forensics)
NTFSNTFS Attributes$STANDARD_INFORMATION vs. $FILE_NAME
NTFSNTFS Attributes What I wish someone had told me when I started learning about File System Forensics
NTFSShort File NamesDeceptive NTFS short file names
NTFSTimestamps/W10NTFS Timestamp changes on Windows 10
NTFSThe “\$Extend\$Deleted” directory
NTFS/FAT/exFATFile System TunnelingFile System Tunneling in Windows
NTFS/FAT32/exFATTimestampsFilesystem Timestamps: What Makes Them Tick?
VariousMaster Boot Record Beginning File System Forensics - learning about the disk and the Master Boot Record (MBR)

File Systems Tools

ToolDescription
Active Disk EditorBtrFS SuperBlock, exFAT, Ext2/Ext3 Superblock, NTFS, ReFS, XFS
X-Ways
MFTECmd
INDXParse
KAPE
HFS+ Journal Parser
NTFS Journal Parser
ISO BusterCD, DVD, Blu Ray, UDF, ISO9660, Joilet, IFO, BUP, VOB file systems