ralphje / imagemounter

Command line utility and Python package to ease the (un)mounting of forensic disk images
MIT License
118 stars 36 forks source link

add ADS support to mount command args #11

Closed magicalbeard closed 7 years ago

magicalbeard commented 7 years ago

I needed support to access $Extend/$UsnJrnl:$Jfor forensic artifact extraction.

From the ntfs-3g docs:

By default, ntfs-3g will only read the unnamed data stream. By using the options "streams_interface=windows", with the ntfs-3g driver (not possible with lowntfs-3g), you will be able to read any named data streams, simply by specifying the stream's name after a colon. For example:

cat some.mp3:artist