1 |
Z. Kai, C. En, and G. Qinquan, "Analysis and implementation of NTFS file system based on computer forensics," Education Technology and Computer Science (ETCS), Vol.1, pp.325-328, 2010.
|
2 |
Byeongyeong Yoo, et al, "A Study on a Carving Method for Deleted NTFS Compressed Files," Human-Centric Computing (HumanCom), 2010 3rd International Conference on. IEEE, pp.1-6, 2010.
|
3 |
R. A. Joyce, J. Powers, and F. Adelstein, "MEGA: A tool for Mac OS X operating system and application forensics," Digital Investigation, Vol.5, pp.S83-S90, 2008.
DOI
|
4 |
A. Case and G. G. Richard, "Advancing Mac OS X rootkit detection," Digital Investigation, Vol.14, pp.S25-S33, 2015.
DOI
|
5 |
A. Burghardt and A. J. Feldman, "Using the HFS+ journal for deleted file recovery," Digital Investigation, Vol.5, pp.S76-S82, 2008.
DOI
|
6 |
HFS+ Deleted File Recovery EnScript [Internet], https://www.kazamiya.net/en/HFSJournalParser.
|
7 |
Apple [Internet], https://developer.apple.com/legacy/library/technotes/tn/tn1150.html.
|
8 |
Apple [Internet], hfs_format.h, http://opensource.apple.com//source/xnu/xnu-1456.1.26/bsd/hfs/hfs_format.h.
|
9 |
D. Comer, "Ubiquitous B-tree," ACM Computing Surveys (CSUR), Vol.11, No.2, pp.121-137, 1979.
DOI
|
10 |
Adobe Systems Incorporated, Document management - Portable document format - Part 1: PDF 1.7, Adobe Systems Incorporated, 2008.
|
11 |
iOS forensic tools [Internet], https://code.google.com/p/iphone-dataprotection/wiki/HFSJournalCarving.
|