diff --git a/0_Master File Table Record/MFT Attributes/0x70_$VOLUME_INFORMATION/$VOLUME_INFORMATION.png b/0_Master File Table Record/MFT Attributes/0x70_$VOLUME_INFORMATION/$VOLUME_INFORMATION.png index 29a0a76..638b6b0 100644 Binary files a/0_Master File Table Record/MFT Attributes/0x70_$VOLUME_INFORMATION/$VOLUME_INFORMATION.png and b/0_Master File Table Record/MFT Attributes/0x70_$VOLUME_INFORMATION/$VOLUME_INFORMATION.png differ diff --git a/0_Master File Table Record/MFT Attributes/0x90_$INDEX_ROOT/$INDEX_ROOT.png b/0_Master File Table Record/MFT Attributes/0x90_$INDEX_ROOT/$INDEX_ROOT.png new file mode 100644 index 0000000..5f35973 Binary files /dev/null and b/0_Master File Table Record/MFT Attributes/0x90_$INDEX_ROOT/$INDEX_ROOT.png differ diff --git a/0_Master File Table Record/MFT Attributes/0x90_$INDEX_ROOT/$INDEX_ROOT.svg b/0_Master File Table Record/MFT Attributes/0x90_$INDEX_ROOT/$INDEX_ROOT.svg index 831e0a0..d402168 100644 --- a/0_Master File Table Record/MFT Attributes/0x90_$INDEX_ROOT/$INDEX_ROOT.svg +++ b/0_Master File Table Record/MFT Attributes/0x90_$INDEX_ROOT/$INDEX_ROOT.svg @@ -17,7 +17,7 @@ version="1.1" inkscape:version="0.91 r13725" sodipodi:docname="$INDEX_ROOT.svg" - inkscape:export-filename="C:\Users\Uproot\Documents\GitHub\Forensic-Posters\4_MFT Attributes\0x30_$FILE_NAME\$FILE_NAME.png" + inkscape:export-filename="C:\Users\Uproot\Documents\GitHub\Forensic-Posters\0_Master File Table Record\MFT Attributes\0x90_$INDEX_ROOT\$INDEX_ROOT.png" inkscape:export-xdpi="300" inkscape:export-ydpi="300"> image/svg+xml - + @@ -94,7 +94,7 @@ x="460.70456" y="407.75677" id="tspan5022" - style="font-size:80px;line-height:89.99999762%">$INDEX_ROO$INDEX_ROOT06 0000 00 24 00 49 00 33 00 30 00 00 24 00 49 00 33 00 30 00 30 00 00 00 01 00 00 00 00 10 00 00 01 00 00 00 30 00 00 00 01 00 00 00 00 10 00 00 01 00 00 0010 00 00 00 B0 00 00 00 B0 00 00 00 01 00 00 00 10 00 00 00 B0 00 00 00 B0 00 00 00 01 00 00 0050 31 00 00 00 00 01 00 88 00 6E 00 01 00 00 00 50 31 00 00 00 00 01 00 88 00 6E 00 01 00 00 0005 00 00 00 00 00 05 00 65 56 92 87 08 9F CE 01 05 00 00 00 00 00 05 00 65 56 92 87 08 9F CE 0165 56 92 87 08 9F CE 01 9C C8 E3 3E A1 CC CF 01 65 56 92 87 08 9F CE 01 9C C8 E3 3E A1 CC CF 01 65 56 92 87 08 9F CE 01 00 00 00 00 00 00 00 00 65 56 92 87 08 9F CE 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 06 24 00 10 03 00 00 A0 00 00 00 00 00 00 00 00 06 24 00 10 03 00 00 A016 01 44 00 6F 00 63 00 75 00 6D 00 65 00 6E 00 16 01 44 00 6F 00 63 00 75 00 6D 00 65 00 6E 00 74 00 73 00 20 00 61 00 6E 00 64 00 20 00 53 00 65 00 74 00 74 00 69 00 6E 00 67 00 73 00 05 00 65 00 74 00 74 00 69 00 6E 00 67 00 73 00 05 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 18 00 00 00 03 00 00 00 01 00 00 00 00 00 00 00 + sodipodi:nodetypes="ccccccccc" /> attribute typetotal sizenon resident flagname lengthname offsetflagsididattribute sizeattribute offsetindex flagattribute nameparent record numberattribute typecollation rulesize of entryclusters/index allocationfirst entry offsettotal size of entriesallocated size of entriesflagsrecord numbersequence numberindex entry sizelength of streamflagsparent record numberparent sequence numberborn timemodified timemft change timeaccess timeallocated sizereal sizeflagsERnamelengthnamespacename @@ -356,59 +499,64 @@ xml:space="preserve" style="font-style:normal;font-weight:normal;font-size:40px;line-height:89.99999762%;font-family:sans-serif;letter-spacing:0px;word-spacing:0px;fill:#000000;fill-opacity:1;stroke:none;stroke-width:1px;stroke-linecap:butt;stroke-linejoin:miter;stroke-opacity:1" x="543.38275" - y="559.258" + y="549.258" id="text5821" sodipodi:linespacing="89.999998%">CommonHeader REsidentHeader fILE_NAMEIndex Entry(fILE_NAME)Attribute + id="tspan5908" /> 48 - filename90 - index root0x780xE00x00 - resident0x000x040x000x180x000x020x060x5E0xC00x180x200x010x00$I3019162130 - filename0x010x10000x010x100xB00xB00x01 - index allocation1262410x880x6E0x0155955/29/2015 1:24:42 AM8/22/2013 3:23:42 AM5/29/2015 1:24:42 AM8/22/2013 3:23:42 AM5/29/2015 1:24:42 AM9/9/2014 10:45:13 PM5/29/2015 1:24:42 AM8/22/2013 3:23:42 AM0x000x000x200x100024060x000xA000000314 Unicode Characters22 Unicode Characters0x01helloworld.txt + id="tspan9668-1">Documents and Settings + y="489.1604" /> Fields + y="489.59302" /> Values + + + IndexRoot + IndexHeader + + Index EntryHeader diff --git a/0_Master File Table Record/MFT Attributes/_NonResident/NonResident.png b/0_Master File Table Record/MFT Attributes/_NonResident/NonResident.png new file mode 100644 index 0000000..9fb84d4 Binary files /dev/null and b/0_Master File Table Record/MFT Attributes/_NonResident/NonResident.png differ diff --git a/0_Master File Table Record/MFT Attributes/_NonResident/NonResident.svg b/0_Master File Table Record/MFT Attributes/_NonResident/NonResident.svg new file mode 100644 index 0000000..644879a --- /dev/null +++ b/0_Master File Table Record/MFT Attributes/_NonResident/NonResident.svg @@ -0,0 +1,888 @@ + + + + + + + + + + + + + + image/svg+xml + + + + + + + + + Non-ResidentATTRIBUTE + 000 80 00 00 00 88 00 00 00 01 02 48 00 00 80 03 00010 00 00 00 00 00 00 00 00 3F 0D 02 00 00 00 00 00020 50 00 04 00 00 00 00 00 00 00 D4 20 00 00 00 00030 A8 0F D2 20 00 00 00 00 A8 0F D2 20 00 00 00 00040 00 00 54 02 00 00 00 00 24 00 4A 00 00 00 00 00050 03 00 E8 01 32 C0 21 04 DC 68 32 80 00 C3 AB 00060 32 80 00 E1 58 B1 32 89 00 C8 44 34 31 77 CA 8B070 09 32 80 00 AA FF 0E 32 80 00 18 3C 16 32 80 00080 8C 12 EB 00 98 C4 D8 8C + + + attribute typetotal sizenon resident flagname lengthname offsetflagsidstarting vcnending vcnoffset to data runscompression unit sizeallocated sizereal sizeinitialized sizeattribute nameSparse0x68DC040x6987C70x1AE0A80x4F25700x58B13A0x67B0E40x7DECFC0x68FF88 + + CommonHeader + DataRuns + + Non-ResidentHeader + + By: Jared AtkinsonTemplate by: Ange Albertini + + 16 - Standard Info0x880x01 - non-resident0x020x480x80000x030x000x20D3F0x500x040x20D400000x20D20FA80x20D20FA8$J0x1E8000x21C00x800x800x890x770x800x800x80 + + Fields + + Values + + + + + + + start + Length + + 32 C0 21 04 DC 68 + + + 2 + 3 + + +