Giter VIP home page Giter VIP logo

rawdir's Introduction

Introduction

The tool resolves content in directories by resolving INDX ($I30) records. It is very powerful and easy to use. It has 2 mode, one verbose output and one compact output. 


Details

The output of mode 2 (verbose) will include the following for each entry within the INDX: 
 -Entry number
 -FileName
 -MFT Ref 
 -MFT Ref SeqNo
 -Parent MFT Ref
 -Parent MFT Ref SeqNo
 -Flags
 -File Create Time
 -File Modified Time
 -MFT Entry modified Time
 -File Last Access Time
 -Allocated Size
 -Real Size
 -NameSpace
 -IndexFlags
 -SubNodeVCN

Timestamps are presented in UTC 0.00 at the nanosec precision. Format is YYYY-MM-DD HH:MM:SS:MSMSMS:NSNSNSNS 


Syntax:
Example printing verbose output from the hidden system folder C:\$Extend 
RawDir.exe 1 C:\$Extend 


Example printing compact output on the root of the C: volume 
RawDir.exe 2 C:\ 


Limitation:
Will not show files marked as deleted. 


Changelog

v1.0.0.4: Fixed bug that caused only one or the other of $INDEX_ROOT/$INDEX_ALLOCATION to be evaluated for content.
v1.0.0.3: Fixed bug when $MFT itself contained an $ATTRIBUTE_LIST. Fixed bug with handling records that was split across dataruns. Increased initialization size of array for runs and vcns which caused it to crash with extreme fragmentation.
v1.0.0.2: Added support for MFT record sizes of 4096 bytes.

rawdir's People

Contributors

jschicht avatar

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.