MFT(Master File Table)の解析 (MFTDump)

MFT

MFTDump

Usage

-------------------------------------------------------------
--              MFTDump - $MFT Dump Tool                   --
--                  Version: V.3.1.0                       --
--     Member of the Malware-Hunters Forensic Toolkit      --
--             Written by Michael G. Spohn                 --
--            http://www.malware-hunters.net               --
-------------------------------------------------------------
--           Use this tool at your own risk                --
--                    NO WARRANTY!                         --
-------------------------------------------------------------

Usage: mftdump [/a] [/d] [/f] [/h] [/l] [/m <str>] [/o <str>] [/s] [/v] [/V] [/z] [$MFT File]
  /a, --ADS             Dump ADS's to stdout
  /d, --debug           Create debug log
  /f, --filenames       Dump filenames to stdout
  /h, --help            Display this notice
  /l, --long            Use long output format
  /m, --hostname=<str>  Hostname (Default: localhost)
  /o, --output=<str>    Output file (Default: mftdump_hostname.txt)
  /s, --short           Use short output format
  /v, --verbose         Chatty output
  /V, --version         Show version and exit
  /z, --zip             Zip output file