Chapter 1. Description and Practice of File Systems and MBR Structure
Chapter 2. Description and Practice of NTFS and VBR Structure
Chapter 3. Understanding MFT
Chapter 4. Description and Practice of the Attribute($STANDARD_INFORMATION) Structure
Chapter 5. Explanation and Practice of the Attribute($FILE_NAME-$DATA) Structure
Chapter 6. MFT Summary
Chapter 7. Challenge Description and Tool Description
Chapter 8. Challenge 1_Problem Solving
Chapter 9. Challenge 2_Problem Solving
Chapter 10. Challenge 3_Problem Solving
Chapter 11. Challenge 4_Problem Solving
Chapter 12. Supplementary Materials for Class
Chapter 13. PETYA Ransomware Recovery
3. Course Target
- Students considering a career in forensics
- People interested in forensic war games (people preparing for hacking competitions)
- People who want to understand the characteristics of NTFS and MFT
4. Instructor Introduction
Security Project - (Current) Researcher in the field of security incident response analysis
- (Former) Researcher at a forensic solutions company
*This lecture is not open to the public and is only shared for corporate lectures.