Trees | Indices | Help |
|
---|
|
An MFT Entry.
Note that MFT entries behave as either files or directories depending on the attributes they have. This object wraps this behavior with convenience methods. Hence callers do not need to manipulate attributes directly.
Nested Classes | |
__metaclass__ Give each object a unique ID. (Inherited from rekall.obj.BaseObject) |
Instance Methods | |||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
Inherited from |
Class Methods | |||
|
Class Variables | |
obj_name = <No name>
(Inherited from rekall.obj.BaseObject)
|
|
obj_parent = <No parent>
(Inherited from rekall.obj.BaseObject)
|
|
obj_producers = None hash(x) (Inherited from rekall.obj.BaseObject) |
Properties | |
mft_entry | |
attributes | |
filename | |
full_path Returns the full path of this MFT to the root. |
|
data_size Search all the $DATA attributes for the allocated size. |
|
indices Returns (usually 1) representation(s) of self usable as dict keys. (Inherited from rekall.obj.Struct) |
|
obj_end (Inherited from rekall.obj.BaseObject) | |
obj_size (Inherited from rekall.obj.Struct) | |
parents Returns all the parents of this object. (Inherited from rekall.obj.BaseObject) |
|
Inherited from |
Method Details |
This must be instantiated with a dict of members. The keys are the offsets, the values are Curried Object classes that will be instantiated when accessed. Args: members: A dict of callables to use for retrieving each member. (Key is member name, value is a callable). Normally these are populated by the profile system struct_size: The size of this struct if known (Can be None).
|
List the files contained in this directory. Note that any file can contain other files (i.e. be a directory) if it has an $I30 stream. Thats is directories may also contain data and behave as files! Returns: An iterator over all INDEX_RECORD_ENTRY. |
Returns an address space which maps the content of the file's data. If this MFT does not contain any $DATA streams, returns a NoneObject(). The returned address space is formed by joining all $DATA streams' run lists in this MFT into a contiguous mapping. |
Property Details |
mft_entry
|
attributes
|
filename
|
full_pathReturns the full path of this MFT to the root.
|
data_sizeSearch all the $DATA attributes for the allocated size.
|
Trees | Indices | Help |
|
---|
Generated by Epydoc 3.0.1 on Mon Oct 9 03:28:14 2017 | http://epydoc.sourceforge.net |