cybersec-analyzing-slack-space-and-file-system-artifacts - Analyze NTFS slack space and forensic artifacts
Examines NTFS slack space, MFT entries, the USN journal, and alternate data streams to recover hidden data and reconstruct file activity.
Tags
Updated: 2026-09-29Capabilities
Typical Inputs
Typical Outputs
What this skill does
- Extract NTFS system artifacts
- Parse MFT entries
- Analyze slack space
- Parse USN journal records
- Detect alternate data streams
- Carve embedded files
Inputs
- NTFS forensic disk image
- Partition offset
- Case output directories
- Slack-space search patterns
Outputs
- Extracted MFT file
- Extracted USN journal
- Extracted transaction log
- Raw slack-space image
- MFT analysis CSV
- USN journal CSV
- Carved embedded files
- Slack-space search results
Requirements
- NTFS forensic disk image
- The Sleuth Kit tools
- MFTECmd
- MFTExplorer
- Python
- analyzeMFT or mft library
- pyusn library
- foremost
- bulk_extractor
