TY - GEN AU - Carrier,Brian TI - File system forensic analysis SN - 0321268172 (pbk.) U1 - 363.25,CAR PY - 2005/// CY - Boston, Mass., London PB - Addison-Wesley KW - Computer science KW - Forensic sciences N1 - Part-1 Foundation (Page-3), Digital investigation foundations (Page-3), Computer foundations(Page-17), Hard disk data acquisition (Page-47), Part-ii Volume Analysis (Page-69), Volume analysis (Page-69), PC-based partitions(Page-81), Server-based partitions (Page-111), Multiple disk volumes (Page-147),Part-iii File System Analysis (Page-173),File system analysis –(Page-173), FAT concepts and analysis (Page-211), FAT data structures (Page-253), NTFS concepts (Page-273), NTFS analysis (Page-301), NTFS data structures (Page-351), Ext2 and Ext3 concepts and analysis –(Page-397),- Ext2 and Ext3 data structures(Page-449), UFS1 and UFS2 concepts and analysis(Page-479), UFS1 and UFS2 data structures (Page-509), Appendix A: The sleuth kit and autopsy.(Page-537) ER -