The $I30 Attribute
The NTFS file system maintains an index of all files/directories that belong to a directory called the $I30 attribute. Every directory in the file system contains a $I30 attribute that must be maintained whenever there are changes to the directory’s contents. When files or folders are removed from the directory, the $I30 index records are rearranged accordingly. However, the rearranging of the index records may leave remnants of the deleted file/folder entry within the slack space. This can be useful in forensics analysis for identifying files that may have existed on the drive.
The $I30 is the “file” name given to NTFS MFT attributes containing filename indexes for directories. NTFS stores the filename contents of the directory ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access