A Journey into NTFS: Part 4

NTFS Attributes

Screenshot of a group of files from the directory C:\Windows in Explorer.exe

$AttrDef File

istat output for MFT entry 4, $AttrDef
Screenshot of the first 1280 bytes of the file $AttrDef
The first 160 bytes of the NTFS metadata file $AttrDef
Hex representation of the $DATA attribute definition in the file $AttrDef
:/mnt/windows_mount# strings -el \$AttrDef
$STANDARD_INFORMATION
$ATTRIBUTE_LIST
$FILE_NAME
$OBJECT_ID
$SECURITY_DESCRIPTOR
$VOLUME_NAME
$VOLUME_INFORMATION
$DATA
$INDEX_ROOT
$INDEX_ALLOCATION
$BITMAP
$REPARSE_POINT
$EA_INFORMATION
$LOGGED_UTILITY_STREAM
fsstat output on a test image

A Few Attributes

istat output for MFT entry 3, the NTFS file $Volume
Raw data of the $STANDARD_INFORMATION attribute from the NTFS file $Volume
Raw data of the $FILE_NAME attribute from the NTFS file $Volume
MFT entry and sequence numbers for the root directory
Raw data of the $OBJECT_ID attribute from the NTFS file $Volume
Converted Object ID from the test NTFS file $Volume
Raw data of the $VOLUME_INFORMATION attribute from the NTFS file $Volume

Additional Resources

Wrapping It All Up

Looking Ahead

--

--

Get the Medium app

A button that says 'Download on the App Store', and if clicked it will lead you to the iOS App store
A button that says 'Get it on, Google Play', and if clicked it will lead you to the Google Play store