Skip to content

Conversation

@loaflover
Copy link
Contributor

so, i cooked for a long time with this. i have a few things id like to say:

  1. extracting the mft file is hard. oof

  2. im not sure if i added enough test files. while i accommodated for all Zone identifier possible values, in my tests i only populated 3 of those, the (by far) most common ones.

  3. i used this:
    https://www.digital-detective.net/forensic-analysis-of-zone-identifier-stream/
    for the possible values, but i also made it somewhat easy to add more

  4. i contemplated adding this to the MFT plugin, since they are similar in behavior, but i saw that all the mft plugin records are timestamp based, while this isnt

anyway, its been a blast writing, except for the hour in which i tried mounting an MFT file like a dumbass, hope this looks good (:

@EinatFox EinatFox linked an issue Dec 4, 2025 that may be closed by this pull request
@loaflover
Copy link
Contributor Author

yo, would love for an update/review when possible (:

no rush, just don't want this to fall through the cracks now that im back to being able to work on this

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Feature/zone identifier

1 participant