The video below shows what happens when files are deleted on an NTFS partition.
This is shown at offset 22 for 2 bytes; i.e. bytes 22 and 23 of the MFT for that entry.
- For an active file the 22nd and 23rd offsets read “01 00″ (in the video its flipped because of the big endian/little endian issue)
- For a deleted file the 22nd and 23rd offsets read “00 00″.