MFT(Master File Table)の解析 (MFTDump)
MFT
MFTDump
Usage
-------------------------------------------------------------
-- MFTDump - $MFT Dump Tool --
-- Version: V.3.1.0 --
-- Member of the Malware-Hunters Forensic Toolkit --
-- Written by Michael G. Spohn --
-- http://www.malware-hunters.net --
-------------------------------------------------------------
-- Use this tool at your own risk --
-- NO WARRANTY! --
-------------------------------------------------------------
Usage: mftdump [/a] [/d] [/f] [/h] [/l] [/m <str>] [/o <str>] [/s] [/v] [/V] [/z] [$MFT File]
/a, --ADS Dump ADS's to stdout
/d, --debug Create debug log
/f, --filenames Dump filenames to stdout
/h, --help Display this notice
/l, --long Use long output format
/m, --hostname=<str> Hostname (Default: localhost)
/o, --output=<str> Output file (Default: mftdump_hostname.txt)
/s, --short Use short output format
/v, --verbose Chatty output
/V, --version Show version and exit
/z, --zip Zip output file