You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
It doesn't look like the MFT Dump outputs Alternate Data Streams, which can be useful to identify files that came from the internet. If we extracted the Resident Files #190 they would appear there, but I believe the ADS should also appear as files in the dump command.
It does look like the entry has an "HasAlternateDataStreams", just doesn't list the names.
The text was updated successfully, but these errors were encountered:
Completely agree with you, it would be useful to get this added. I had a quick look and it seems like the underlying library doesn't show the ADS when exporting to CSV format. We'll either need to look at getting this added to the library, or figure out a way to parse it out on the chainsaw side.
I need to think about how we should do this cleanly.
It doesn't look like the MFT Dump outputs Alternate Data Streams, which can be useful to identify files that came from the internet. If we extracted the Resident Files #190 they would appear there, but I believe the ADS should also appear as files in the dump command.
It does look like the entry has an "HasAlternateDataStreams", just doesn't list the names.
The text was updated successfully, but these errors were encountered: