FLS & Mactime
Last updated
Last updated
fls
is a part of the sleuth autopsy kit - designed to extract filename and metadata information for files. there are three different types of data to collect:
allocated files - normally active files. one would see when performing directory listing
deleted files - unallocated files whose name structures exist. sometime metadata of deleted files can contain full path info
orphaned file represent data from unallocated metadata structures where parent folder is not longer available
takes a bodyfile (from either fls
or ) and parses into format that can be analysed: