Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

MFT File Not Available #9

Closed
binglot opened this issue May 27, 2014 · 5 comments
Closed

MFT File Not Available #9

binglot opened this issue May 27, 2014 · 5 comments
Labels

Comments

@binglot
Copy link

binglot commented May 27, 2014

In the provided VM of SIFT 3.0, I mounted an NTFS partition with all the extra parameters (show_sys_files, etc.) and to my surprise the $MFT file wasn't available. All other files seem to be there (e.g. $MFTMirr) except this one. Why Googling the problem I came across this: "Note that even when show_sys_files is specified, "$MFT" may will not be visible due to bugs/mis-features in glibc." (Source: http://manpages.ubuntu.com/manpages/gutsy/man8/ntfsmount.8.html).

Another surprise was when I looked at the bodyfile generated by log2timeline and it contained MFT entries. When I dumped MFT using icat and then parsed it with log2timeline, the number of L2T generated entries was almost identical. Any ideas?

Thanks,
Bart

@ekristen
Copy link
Contributor

I'll have to test this.

@ekristen
Copy link
Contributor

@SANS-SIFT have you ran into any issues with $MFT not being available?

@SIFT-OWNER
Copy link
Contributor

It is there. But not listed. Need to run similar command

cp $MFT /temp/MFT

Best, Rob

Sent from my Mobile Phone

On Aug 30, 2014, at 10:28 AM, Erik Kristensen notifications@github.com wrote:

@SANS-SIFT have you ran into any issues with $MFT not being available?


Reply to this email directly or view it on GitHub.

@ekristen
Copy link
Contributor

@baltek hope that helps, I'm closing this ticket, if you have more questions feel free to comment again.

@binglot
Copy link
Author

binglot commented Aug 31, 2014

Hi Erik,

Thank you for your reply and following up with the question. I'll test it
tomorrow at work and should I have any problems I'll get back to you.

Regards,
Bart

Bartosz Inglot
inglotbartosz@gmail.com

On 31 August 2014 14:07, Erik Kristensen notifications@github.com wrote:

@baltek https://github.com/baltek hope that helps, I'm closing this
ticket, if you have more questions feel free to comment again.


Reply to this email directly or view it on GitHub
#9 (comment).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

3 participants