Open jaredcatkinson opened 8 years ago
Add -Deleted parameter to Get-ForensicFileRecord which will only return the records of deleted files.
This should look into parsing the $MFT file's Bitmap values. I believe they are used by the File System to determine what MFT File Records are "unallocated" and thus representing deleted files.
Add -Deleted parameter to Get-ForensicFileRecord which will only return the records of deleted files.