6Windows Forensics
Windows, being the most widely used operating system in the world, is the reason a significant focus of digital forensics research is aimed at it. Although the operating system does not specifically maintain records for forensic purposes, what it does is generate a wealth of data related to user activities and preferences. This data is used by the system to enhance usability, such as providing quick access to recently opened files or improving network connections. For forensic professionals, this wealth of data provides an opportunity to piece together a timeline of user activities on a Windows device and get insights into a user’s behavior. Understanding the Windows operating system and the various data artifacts it produces is an essential skill for any digital forensics practitioner.
6.1 New Technology File System (NTFS)
The New Technology File System (NTFS)1 provides several advantages over other Table 6.1 like File Allocation Table (FAT) and Extended File Allocation Table (exFAT) including features like:
- Metadata: NTFS stores detailed metadata for each file, including security attributes, access control lists, and owner information.
- Advanced file structure: NTFS supports advanced file structures such as alternate data streams, which allow multiple data streams to be associated with a single file.
- Journaling: NTFS includes a journaling feature that helps ensure the consistency and integrity of the file system in the event of a system crash or power ...
Get Practical Cyber Intelligence now with the O’Reilly learning platform.
O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.