New jIIr post: Extracting ZeroAccess from NTFS Extended Attributes journeyintoir.blogspot.com/2… examining NTFS Extended Attributes #DFIR
5
10
9
@corey_harrell I know TSK's fls will show alt data streams ("fls -rp <img> | grep ':.*:'"). Does it also have a mode where it shows $EA?
1
@hal_pomeranz I looked at all fls switches & it doesn't show $EA. istat doesn't have a recursive mode either. One reason I used a mft parser
1
@corey_harrell Of course istat has a recursive mode-- it's called bash shell scripting... :-)
Dec 12, 2012 · 12:50 PM UTC
1

