Filesystem Journal Forensics
- David Cowen
- Wednesday, November 5th, 8:15pm - 9:15pm
Journaled file systems have been a part of modern file systems for years, but the science of computer forensics has only been approaching them mainly as a method of recovering deleted files. In this talk we will outline the three major file systems in use today that utilize journaling (NTFS, EXT3/4, HFS+) and explain what is stored and its impact on your investigations. We will discuss NTFS and new analysis techniques:
- Recover data hidden or destroyed by anti-forensics
- Determine exact deletion times
- Determine what was being accessed and how often
The following bonus sessions are open to all paid attendees at no additional cost. There are many different types of events that fall into these categories:
- SANS@Night: Evening presentations given after day courses have ended. This category includes Keynotes.
- Special Events: SANS-hosted events and other non-technical recreational offerings. This category includes, but is not limited to, Receptions and Information Tables.