In this video from our NTFS Forensics course our instructor, Divya Lakshmanan, will show you how to process the $DATA attribute of the $Boot file in the NT File System. How to locate it? Why is it useful? What can you find there? All of this and more, all in under 10 minutes, in the video below :). If you want to get your forensic skills up to this level consider joining the full course, but for now just enjoy the video!
[custom-related-posts title="Check out courses instructed by Divya: " none_text="None found" order_by="title" order="ASC"]
Author
Latest Articles
- BlogApril 7, 2022Detecting Fake Images via Noise Analysis | Forensics Tutorial [FREE COURSE CONTENT]
- BlogMarch 2, 2022Windows File System | Windows Forensics Tutorial [FREE COURSE CONTENT]
- BlogAugust 17, 2021PowerShell in forensics - suitable cases [FREE COURSE CONTENT]
- OpenMay 20, 2021Photographic Evidence and Photographic Evidence Tampering
Subscribe
Login
0 Comments