Open mirh opened 1 year ago
shell disk=1 volume=3 disk1:volume3:> ls Inode | Type | Name | Size | Creation Date | Attributes --------------------------------------------------------------------------------------------- 4 | | $AttrDef | 2560 | 2021-02-18 05:45:18 | Hi Sy 8 | | $BadClus | 0 | 2021-02-18 05:45:18 | Hi Sy | ADS | $Bad | 510905020416 | | 6 | | $Bitmap | 15591584 | 2021-02-18 05:45:18 | Hi Sy | ADS | $SRAT | 68 | | 7 | | $Boot | 8192 | 2021-02-18 05:45:18 | Hi Sy 11 | DIR | $Extend | | 2021-02-18 05:45:18 | Hi Sy 2 | | $LogFile | 67108864 | 2021-02-18 05:45:18 | Hi Sy 0 | | $MFT | 2073034752 | 2021-02-18 05:45:18 | Hi Sy 1 | | $MFTMirr | 4096 | 2021-02-18 05:45:18 | Hi Sy 4502 | DIR | $Recycle.Bin | | 2019-12-07 10:14:52 | Hi Sy 9 | | $Secure | 0 | 2021-02-18 05:45:18 | Hi Sy 10 | | $UpCase | 131072 | 2021-02-18 05:45:18 | Hi Sy | ADS | $Info | 32 | | 3 | | $Volume | 0 | 2021-02-18 05:45:18 | Hi Sy 154204 | DIR | $WINDOWS.~BT | | 2021-11-02 22:52:59 | 50617 | DIR | $Windows.~WS | | 2022-02-06 19:18:00 | Hi Ni 156 | DIR | $WinREAgent | | 2023-01-10 22:38:03 | Hi mft.record disk=1 volume=3 MFT (inode:0) for \\.\PhysicalDrive1 > Volume:3 -----------------------------------------------
shell disk=1 volume=3 disk1:volume3:> ls
Inode | Type | Name | Size | Creation Date | Attributes --------------------------------------------------------------------------------------------- 4 | | $AttrDef | 2560 | 2021-02-18 05:45:18 | Hi Sy 8 | | $BadClus | 0 | 2021-02-18 05:45:18 | Hi Sy | ADS | $Bad | 510905020416 | | 6 | | $Bitmap | 15591584 | 2021-02-18 05:45:18 | Hi Sy | ADS | $SRAT | 68 | | 7 | | $Boot | 8192 | 2021-02-18 05:45:18 | Hi Sy 11 | DIR | $Extend | | 2021-02-18 05:45:18 | Hi Sy 2 | | $LogFile | 67108864 | 2021-02-18 05:45:18 | Hi Sy 0 | | $MFT | 2073034752 | 2021-02-18 05:45:18 | Hi Sy 1 | | $MFTMirr | 4096 | 2021-02-18 05:45:18 | Hi Sy 4502 | DIR | $Recycle.Bin | | 2019-12-07 10:14:52 | Hi Sy 9 | | $Secure | 0 | 2021-02-18 05:45:18 | Hi Sy 10 | | $UpCase | 131072 | 2021-02-18 05:45:18 | Hi Sy | ADS | $Info | 32 | | 3 | | $Volume | 0 | 2021-02-18 05:45:18 | Hi Sy 154204 | DIR | $WINDOWS.~BT | | 2021-11-02 22:52:59 | 50617 | DIR | $Windows.~WS | | 2022-02-06 19:18:00 | Hi Ni 156 | DIR | $WinREAgent | | 2023-01-10 22:38:03 | Hi
mft.record disk=1 volume=3
MFT (inode:0) for \\.\PhysicalDrive1 > Volume:3 -----------------------------------------------
Signature : FILE Update Offset : 48 Update Number : 3 $LogFile LSN : 305819962804 Sequence Number : 1 Hardlink Count : 1 Attribute Offset : 56 Flags : In use Real Size : 888 Allocated Size : 1024 Base File Record : 0000000000000000h Next Attribute ID : 13 MFT Record Index : 0 Update Seq Number : 1714 Update Seq Array : 01150000
+-------------------------------------------------------------------------------------------------------------+ | 4 | $BITMAP | True | 254944 | Index Node Used : 1752184 | | | Raw address: 0000c0000290h | | | | +-------------------------------------------------------------------------------------------------------------+
But last but not least > logfile.dump disk=1 volume=3 output=log.log format=raw
[+] Opening \?\Volume{3de295f9-1d5e-4f1d-bbce-fb5e97329559}\ [+] Reading $LogFile record [+] $LogFile size : 64.00 MiBs [+] Creating log.log [!] Unable to find corresponding $DATA attribute [+] Processing data: 0.00 byte[+] Closing volume
[+] Closing volume
Signature : FILE Update Offset : 48 Update Number : 3 $LogFile LSN : 305819962804 Sequence Number : 1 Hardlink Count : 1 Attribute Offset : 56 Flags : In use Real Size : 888 Allocated Size : 1024 Base File Record : 0000000000000000h Next Attribute ID : 13 MFT Record Index : 0 Update Seq Number : 1714 Update Seq Array : 01150000
Attributes:
+-------------------------------------------------------------------------------------------------------------+ | 4 | $BITMAP | True | 254944 | Index Node Used : 1752184 | | | Raw address: 0000c0000290h | | | | +-------------------------------------------------------------------------------------------------------------+
LogFile from \.\PhysicalDrive1 > Volume:3
[+] Opening \?\Volume{3de295f9-1d5e-4f1d-bbce-fb5e97329559}\ [+] Reading $LogFile record [+] $LogFile size : 64.00 MiBs [+] Creating log.log [!] Unable to find corresponding $DATA attribute [+] Processing data: 0.00 byte[+] Closing volume
[+] Closing volume