New jIIr post: Extracting ZeroAccess from NTFS Extended Attributes journeyintoir.blogspot.com/2… examining NTFS Extended Attributes #DFIR
5
10
9
Replying to @corey_harrell
@corey_harrell I know TSK's fls will show alt data streams ("fls -rp <img> | grep ':.*:'"). Does it also have a mode where it shows $EA?

Dec 12, 2012 · 9:51 AM UTC

1
Replying to @hal_pomeranz
@hal_pomeranz I looked at all fls switches & it doesn't show $EA. istat doesn't have a recursive mode either. One reason I used a mft parser
1
@corey_harrell Of course istat has a recursive mode-- it's called bash shell scripting... :-)
1