Explain the possible forensic relevance of a drive’s volume label including how a volume label is assigned to a drive.
$MFT
Describes all files on the volume. Names, timestamps, clusters,
attributes, security.
• A relational database table containing information about all
files. Similar to a Table of Contents.
• Every file and directory on record has an entry (record) in the
$MFT.
• Each record is 1024 bytes.
• Can have slack space> can hide information there
• If a file is relatively small in size (less than 600 bytes ie a
cookie), the data is stored in the MFT (rather than the data area
to speed up access). Increases performance.> RESIDENT
• The only information on a NTFS volume that is not stored in the
MFT is the volume boot sector. The volume boot sector starts at
sector 0.
Get Answers For Free
Most questions answered within 1 hours.