Forensics: MFT FILE* and FILE0

If the MFT Entry for an NTFS volume startswith FILE0, rather than FILE*, this means that the NTFS volume has probably been formatted with Windows XP, or newer.

If the MFT Entries start with FILE*,  it means that the volume was probably formatted with Windows 2K or older.

In the article on “How to view the MFT in EnCase” the MFT shown is FILE0, meaning the drive was formatted with Windows XP or a newer O/S

 This is useful informaiton in computer forensics examination as a quick look at the MFT can indicate how the hard drive was formatted, also, keyword searching for FILE* or FILE0 can reveal previous partitions on the hard drive.


Leave a Reply

Fill in your details below or click an icon to log in: Logo

You are commenting using your account. Log Out /  Change )

Google+ photo

You are commenting using your Google+ account. Log Out /  Change )

Twitter picture

You are commenting using your Twitter account. Log Out /  Change )

Facebook photo

You are commenting using your Facebook account. Log Out /  Change )


Connecting to %s

%d bloggers like this: