Dataset for forensic analysis of B-tree file system
Dataset for forensic analysis of B-tree file system
Blog Article
Since B-tree file system (Btrfs) is set to become de facto standard file system on Linux (and Linux based) operating systems, Btrfs dataset for forensic Mounting Brackets analysis is of great interest and immense value to forensic community.This article presents a novel dataset for forensic analysis of Btrfs that was collected using a proposed data-recovery HID Lighting Kit procedure.The dataset identifies various generalized and common file system layouts and operations, specific node-balancing mechanisms triggered, logical addresses of various data structures, on-disk records, recovered-data as directory entries and extent data from leaf and internal nodes, and percentage of data recovered.