Have a question?
Message sent Close

Cyber Forensics: Analyzing Data Streams in NTFS

Adding and Analyzing Resident and Non-Resident Data in NTFS Data Streams and the Master File Table using Hex Editors.
Instructor:
Cyber Imaginations
627 students enrolled
English [Auto]
Basic understanding and importance of Data Streams
Adding Resident and Non-Resident Data in the Data Streams
Analyzing Short and Long Filenames using WinHex
Analyzing Resident and Non-Resident Data using WinHex
Verifying existence of Non-Resident Data using HxD

The course will help students to learn about the basics of Microsoft Windows File System (NTFS), the Master File Table (MFT) and how data is stored in data streams, both primary and alternate. Students will also get to differentiate between resident and non-resident data and learn how to hide data in the ADS. It would also enable students to analyze the data inside and outside of the MFT and to locate the specific cluster/sector on the hard disk where this data is actually stored. Moreover the students will be able to:

  • Understand the basics of Alternate Data Streams (ADS), their usage and history
  • Adding resident (less than 512 bytes) and non-resident (more than 512 bytes) data in both alternate and primary data streams
  • Analyzing the resident data in any stream by locating it inside the MFT using a common Hex Editor
  • Analyzing the non-resident data in any stream by locating its actual cluster and sector address on the disk
  • Verifying the presence of non-resident data in any data stream with the help of another Hex Editor
  • Practically experiment common Forensics tools and Hex Editors for analyzing data in the MFT and otherwise.

This course will turn out to be very useful for the students who want to understand the basics of computer forensics and file systems as it provides insight to analyzing data stored in the data streams.

You can view and review the lecture materials indefinitely, like an on-demand channel.
Definitely! If you have an internet connection, courses on Udemy are available on any device at any time. If you don't have an internet connection, some instructors also let their students download course lectures. That's up to the instructor though, so make sure you get on their good side!

Be the first to add a review.

Please, login to leave a review
1cebb0cb635ee30d790b71ec5bd0cf28
Course available for 2 days
30-Day Money-Back Guarantee

Includes

1 hours on-demand video
Full lifetime access
Access on mobile and TV
Certificate of Completion

External Links May Contain Affiliate Links read more

Join our Telegram Channel To Get Latest Notification & Course Updates!
Join Our Telegram For FREE Courses & Canva PremiumJOIN NOW