Analyzing Slack Space And File System Artifacts

Examine NTFS slack space, MFT entries, the USN Change Journal, and Alternate Data Streams (ADS) to recover hidden or residual data, reconstruct deleted-file metadata, and reconstruct available file-system change activity from USN records. Use during deep forensic analysis of an NTFS image when standard file recovery is insufficient, such as hunting for data hidden in ADS.

gabrielmoreira Updated 17 repo stars

File contents

gabrielmoreira/agent-skills-mirror/tree/main/mirrors/repos/mukul975@Anthropic-Cybersecurity-Skills/skills/analyzing-slack-space-and-file-system-artifacts commit 5aeefe3f0d

Frequently asked questions

npx skillmds@latest add gabrielmoreira/analyzing-slack-space-and-file-system-artifacts