New jIIr post: Extracting ZeroAccess from NTFS Extended Attributes journeyintoir.blogspot.com/2… examining NTFS Extended Attributes #DFIR
5
10
9
@corey_harrell I know TSK's fls will show alt data streams ("fls -rp <img> | grep ':.*:'"). Does it also have a mode where it shows $EA?
Dec 12, 2012 · 9:51 AM UTC
1

