| name | analyzing-slack-space-and-file-system-artifacts |
| description | Examine file system slack space, MFT entries, USN journal, and alternate data streams to recover hidden data and reconstruct file activity on NTFS volumes. Use when working with analyzing slack space and file system artifacts. |
| domain | cybersecurity |
| tags | ["forensics","slack-space","ntfs","mft","usn-journal","alternate-data-streams","file-system-analysis"] |
| subdomain | digital-forensics |
| version | 1.0 |
| author | oyi77 |
| license | Apache-2.0 |
| nist_csf | ["RS.AN-01","RS.AN-03","DE.AE-02","RS.MA-01"] |
Analyzing Slack Space And File System Artifacts
Overview
Cybersecurity skill for analyzing slack space and file system artifacts. Follows industry best practices and security standards.
When to Use
Trigger phrases:
-
"analyzing slack space and file system artifacts"
-
"Examine file system slack space, MFT entries, USN journal, and alternate data st"
-
When searching for hidden or residual data in file system slack space
-
For analyzing NTFS Master File Table (MFT) entries for deleted file metadata
-
When reconstructing file operations from the USN Change Journal
-
For detecting Alternate Data Streams (ADS) used to hide data or malware
-
During deep forensic analysis requiring examination beyond standard file recovery
When NOT to Use
- When you lack proper authorization for testing
- For production systems without change management
- When the task requires legal or compliance expertise beyond technical scope
Prerequisites
- Forensic disk image with NTFS file system
- The Sleuth Kit (TSK) tools: istat, icat, fls, blkls, blkstat
- MFTECmd (Eric Zimmerman) for MFT parsing
- MFTExplorer for interactive MFT analysis
- Understanding of NTFS structures (MFT, $UsnJrnl, $LogFile, ADS)
- Python with analyzeMFT or mft library for automated parsing
Workflow
import re
IOC_PATTERNS = {
"ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",
"domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",
"hash_md5": r"\b[a-f0-9]{32}\b",
"hash_sha256": r"\b[a-f0-9]{64}\b",
}
def extract_iocs(text: str) -> dict:
return {k: re.findall(v, text) for k, v in IOC_PATTERNS.items()}