Skip to Main Content
NTFS, which restores and manages the important data, is a common file system in Windows Operating System,. Tapping and analyzing the useful data of the NTFS file system has become an important means of current computer forensic. Through detailed analysis and research on the storage principles of the NTFS file system, the object-oriented method is put forward to design NTFS file parsing system. This system parses the binary data stored in disk, achieving the total analysis of both the normal files and the deleted files. Then, all the data retrieved can be restored into the form of a friendly user interface which can provide a reliable data source for the computer forensics.