Processing the $Boot File | NTFS Tutorial | eForensics Magazine

preview_player
Показать описание
In this video from our NTFS Forensics course our instructor, Divya Lakshmanan, will show you how to process the $DATA attribute of the $Boot file in the NT File System. How to locate it? Why is it useful? What can you find there? All of this and more, all in under 10 minutes, in the video below :). If you want to get your forensic skills up to this level consider joining the full course, but for now just enjoy the video!

HAKIN9 MEDIA MAGAZINE FAMILY:

The techniques described in our content may only be used in private, local networks and with the owner's permission. Hakin9 Media sp. z o.o. SK holds no responsibility for misuse of the presented techniques or consequent data loss.
Рекомендации по теме