Legal Cyber Academy
BookPaidCurrent

File System Forensic Analysis

Brian Carrier · Addison-Wesley Professional · First edition · 2005

Identifier: ISBN 978-0-321-26817-4

Access and status

Cost

Paid

Costs money to buy outright — a book, a licence, a registration.

Status

Current

Current as at the verification date below. Standards and tools both move — confirm at source before you rely on it.

What it is

A byte-level reference to volume and file system structures: DOS/MBR, GPT, Apple, BSD and Solaris partitioning, then the on-disk layout and recovery behaviour of FAT, NTFS, Ext2/Ext3 and UFS. Each file system gets both a conceptual model and the actual data structure field listings.

Who it is for, and when

This is the book you open when a tool tells you something and you need to prove it from the raw structures: why a deleted file's data is still addressable, what an $MFT entry actually says, how slack arises. Essential for anyone who will be cross-examined on the mechanism behind a recovery, and for anyone writing or validating parsing code. The author wrote The Sleuth Kit, and the model in the book is the model the tool implements.

What it does not cover

Written against XP/2000-era NTFS and pre-ext4 Linux. The on-disk structures it documents have barely changed and still hold, but there is nothing here on ext4, exFAT, APFS, ReFS, SSD wear-levelling and TRIM, or full-disk encryption. The Sleuth Kit appendix describes a 2005 command-line era that today's Autopsy does not resemble. Print is out of print; the e-book is still sold.

Go to the source

Open at informit.com (opens in a new tab)

https://www.informit.com/store/file-system-forensic-analysis-9780321268174

Details

Type
Book
Written for
AdvancedWorking examinerAdvanced, Working examiner
Author
Brian Carrier
Publisher
Addison-Wesley Professional
Version verified
First edition
Year
2005
Identifier
ISBN 978-0-321-26817-4
Topics
file-systems, imaging, foundations
Checked at source
  • A Windows tool that mounts raw, forensic, and virtual machine disk images as complete physical disks rather than as individual volumes, which is what lets Windows and other software treat an image as a real attached drive. It also offers Windows authentication bypass, launching virtual machines from volume shadow copies, and BitLocker handling.

  • SWGDE's guidance on acquiring data from computers and computer storage, including write blocking, live versus dead acquisition, verification and the handling of encrypted and self-encrypting media. The version verified here is 17-F-002-2.1 dated 5 August 2025.

  • A commercial Windows forensic examination environment from the German publisher X-Ways Software Technology AG, built on their WinHex disk editor and known for running from a portable installation with very low overhead. Licences are perpetual and protected by a local or network dongle, or by a bring-your-own-device arrangement.

  • The long-running course textbook for digital forensics programmes: lab setup and policy, acquisition, operating-system and email and mobile artifacts, report writing and expert-witness basics, with end-of-chapter exercises. Written to be taught from, not read at the bench.

  • The report from the first Digital Forensic Research Workshop, held in 2001, which set out a research agenda and a shared vocabulary for a field that at that point had neither. It is the document that proposed the examination process framework and the term 'digital forensic science', and it is conventionally cited as Palmer (2001); DFRWS's own page for it names no individual author.