Extract $bitmap file from NTFS Image

匿名 (未验证) 提交于 2019-12-03 10:10:24

问题:

Does anyone know of any software that can extract the $bitmap file from NTFS images?

Or does anyone know of any site that documents NTFS enough so that I can code this myself?

(I want to read the $bitmap so I can identify what clusters are not in use, so they can be removed from the images.)

回答1:

There's one short paragraph in this early publication by a talented person:

http://www.alex-ionescu.com/NTFS.pdf



回答2:

I answered this one in a different place, but on a live Windows machine the best answer is probably to use FSCTL_GET_VOLUME_BITMAP. This will reflect any changes the FS knows about that aren't on the disk.



回答3:

There is also "Forensic File Systems" by Brian Carrier. It does explain NTFS in detail. ntfs.org also is helpful.

Since $Bitmap is a system file, you can't open it up and read it. Also beware that if the disk is in use, it can change.



标签
易学教程内所有资源均来自网络或用户发布的内容,如有违反法律规定的内容欢迎反馈
该文章没有解决你所遇到的问题?点击提问,说说你的问题,让更多的人一起探讨吧!