gptkbp:instanceOf
|
file system metadata structure
|
gptkbp:abbreviation
|
gptkb:MFT
|
gptkbp:analyzes
|
forensic tools
|
gptkbp:canBeFragmented
|
yes
|
gptkbp:canGrowOn
|
yes
|
gptkbp:compatibleWith
|
gptkb:FAT_file_systems
|
gptkbp:contains
|
timestamps
permissions
file size
file name
file attributes
data location
data runs
security identifier
|
gptkbp:corruptedBy
|
yes
|
gptkbp:createdBy
|
gptkb:Microsoft
|
gptkbp:entryDeletedBy
|
marking as unused
|
gptkbp:entryIdentifiedBy
|
file reference number
|
gptkbp:entryMayBeRecoveredBy
|
data recovery tools
|
gptkbp:entryReusedBy
|
new files
|
gptkbp:entrySize
|
typically 1 KB
|
gptkbp:firstEntry
|
gptkb:$MFT
|
gptkbp:hasEntrance
|
record producer
|
gptkbp:hasEntry
|
index allocation
attribute list
data attribute
index root
non-resident data
resident data
|
https://www.w3.org/2000/01/rdf-schema#label
|
Master File Table
|
gptkbp:introducedIn
|
gptkb:Windows_NT_3.1
|
gptkbp:mirroredBy
|
$MFTMirr
|
gptkbp:numberOfLocations
|
information about every file and directory
|
gptkbp:purpose
|
enable fast file access
support file system integrity
track files and directories
|
gptkbp:recordedAt
|
gptkb:NTFS_volume
|
gptkbp:requires
|
NTFS operation
|
gptkbp:residesIn
|
beginning of NTFS volume
|
gptkbp:restored
|
gptkb:chkdsk
|
gptkbp:specialEntry
|
gptkb:$LogFile
$BadClus
$Bitmap
$Boot
$Extend
$MFTMirr
$Secure
$UpCase
$Volume
|
gptkbp:usedIn
|
gptkb:NTFS
|
gptkbp:bfsParent
|
gptkb:NTFS
|
gptkbp:bfsLayer
|
6
|