File System Forensic Analysis
Brian Carrier · Addison-Wesley Professional · First edition · 2005
Identifier: ISBN 978-0-321-26817-4
Access and status
Cost
Paid
Costs money to buy outright — a book, a licence, a registration.
Status
Current
Current as at the verification date below. Standards and tools both move — confirm at source before you rely on it.
What it is
A byte-level reference to volume and file system structures: DOS/MBR, GPT, Apple, BSD and Solaris partitioning, then the on-disk layout and recovery behaviour of FAT, NTFS, Ext2/Ext3 and UFS. Each file system gets both a conceptual model and the actual data structure field listings.
Who it is for, and when
This is the book you open when a tool tells you something and you need to prove it from the raw structures: why a deleted file's data is still addressable, what an $MFT entry actually says, how slack arises. Essential for anyone who will be cross-examined on the mechanism behind a recovery, and for anyone writing or validating parsing code. The author wrote The Sleuth Kit, and the model in the book is the model the tool implements.
What it does not cover
Written against XP/2000-era NTFS and pre-ext4 Linux. The on-disk structures it documents have barely changed and still hold, but there is nothing here on ext4, exFAT, APFS, ReFS, SSD wear-levelling and TRIM, or full-disk encryption. The Sleuth Kit appendix describes a 2005 command-line era that today's Autopsy does not resemble. Print is out of print; the e-book is still sold.
Go to the source
Open at informit.com (opens in a new tab)https://www.informit.com/store/file-system-forensic-analysis-9780321268174
Details
- Type
- Book
- Written for
- AdvancedWorking examinerAdvanced, Working examiner
- Author
- Brian Carrier
- Publisher
- Addison-Wesley Professional
- Version verified
- First edition
- Year
- 2005
- Identifier
- ISBN 978-0-321-26817-4
- Topics
- file-systems, imaging, foundations
- Checked at source
Related entries
A Windows tool that mounts raw, forensic, and virtual machine disk images as complete physical disks rather than as individual volumes, which is what lets Windows and other software treat an image as a real attached drive. It also offers Windows authentication bypass, launching virtual machines from volume shadow copies, and BitLocker handling.
SWGDE's guidance on acquiring data from computers and computer storage, including write blocking, live versus dead acquisition, verification and the handling of encrypted and self-encrypting media. The version verified here is 17-F-002-2.1 dated 5 August 2025.
X-Ways Forensics
PaidA commercial Windows forensic examination environment from the German publisher X-Ways Software Technology AG, built on their WinHex disk editor and known for running from a portable installation with very low overhead. Licences are perpetual and protected by a local or network dongle, or by a bring-your-own-device arrangement.
The long-running course textbook for digital forensics programmes: lab setup and policy, acquisition, operating-system and email and mobile artifacts, report writing and expert-witness basics, with end-of-chapter exercises. Written to be taught from, not read at the bench.
The report from the first Digital Forensic Research Workshop, held in 2001, which set out a research agenda and a shared vocabulary for a field that at that point had neither. It is the document that proposed the examination process framework and the term 'digital forensic science', and it is conventionally cited as Palmer (2001); DFRWS's own page for it names no individual author.