Description


This plugin has been designed as primarily as a classroom aid to assist in the examination of MFT records.

The script allows the user to bookmark the MFT record for the highlighted file, the MFT records for a maximum of 20 blue-checked files or folders, or the MFT record highlighted in the GUI (it's only necessary to highlight the first byte of any such record).

The script will bookmark each MFT-record's 'FILE' header, the first 4-bytes of each of its MFT record-attributes, and its 0xffffffff end-marker. Each attribute's length and instance-ID will be bookmarked. The latter can prove useful in identifying how the associated file has been manipulated. For example, it may corroborate the fact that the file has been renamed.

These bookmarks will be grouped into a sub-folder, one per each file/folder that's been processed.

Coupled with the MFT-record bookmarking functionality, the script provides the option to decode both single and multiple NTFS dataruns.

Prior to decoding, multiple dataruns must be highlighted from beginning to end. Only the first byte of a single datarun needs to be highlighted.

When decoding multiple dataruns, the script will assume that the first run marks the start of a file and calculate the starting cluster of each run accordingly.

Note that the datarun decoding functionality is designed to operate in isolation; it does not take fix-up sequences into account.

The script also has a highlighted-data bookmark function. This is similar to that provided by EnCase, but with the added benefit of being invokable using a keyboard shortcut.

The script will produce coloured bookmarks when run under EnCase 8.09 or later.

This script was developed for use in EnCase training. For more details, please click the following link:

Releases

Release
Size
Date
MFT Record Bookmark Plugin 7.1.0
  |  
Aug 1, 2024
More info Less info
Product compatibility
Release notes

Tested with:
EnCase Forensic 21.01.00.68

Languages
English

Unsubscribe from notifications

You are receiving release updates for this item because you have subscribed to the following products:
If you unsubscribe, you will no longer receive any notifications for these products.
Tip: to update your subscription preferences, go to Manage Subscriptions from your Dashboard, uncheck the products you no longer want to receive notifications for, and click 'Save'.

Marketplace Terms of Service

In order to continue, you must accept the updated Marketplace Terms of Service
Since you are downloading an app from the OpenText Marketplace, you need to accept the updated Marketplace Terms of Service before you can continue. Use the link to review the Marketplace Terms of Service. Once complete check the, "I accept the Marketplace Terms of Service" box below and click accept to continue your download.


Your download has begun...

Your download has begun

Related content and resources

Your browser is not supported!

Please upgrade to one of the following broswers: Internet Explorer 11 (or greater) or the latest version of Chrome or Firefox

release-rel-2025-2-1-6322 | Wed Feb 5 16:30:41 PST 2025