analyzing-slack-space-and-file-system-artifacts - Analyze NTFS Slack Space and File System Artifacts
Examines NTFS slack space, MFT entries, USN journal records, and alternate data streams to recover hidden data and reconstruct file activity.
Tags
Updated: 2026-09-28Capabilities
Typical Inputs
Typical Outputs
What this skill does
- Extract NTFS system artifacts
- Analyze MFT entries
- Detect deleted files
- Analyze slack space
- Parse USN journal records
- Detect alternate data streams
- Carve embedded files
Inputs
- NTFS forensic disk image
- NTFS system files
- MFT data
- USN change journal
- File system metadata
Outputs
- Extracted MFT file
- Extracted USN journal
- Extracted transaction log
- Raw slack-space file
- MFT analysis CSV
- USN journal CSV
- Slack-space string report
- Carved embedded files
- Alternate-data-stream listing
Requirements
- NTFS forensic disk image
- Sleuth Kit tools
- MFTECmd
- MFTExplorer
- Python
- analyzeMFT or mft library
- Knowledge of NTFS structures
