Skip to content

MFT Alternate Data Streams #191

Closed
@IppSec

Description

@IppSec

It doesn't look like the MFT Dump outputs Alternate Data Streams, which can be useful to identify files that came from the internet. If we extracted the Resident Files #190 they would appear there, but I believe the ADS should also appear as files in the dump command.

It does look like the entry has an "HasAlternateDataStreams", just doesn't list the names.

Metadata

Metadata

Assignees

Labels

enhancementNew feature or request

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions