Skip main navigation

Attribute 0x30 $FILE_NAME

Article detailing an overview of NT File System $MFT file segment entry (record) attribute 0x30 $FILE_NAME.
© PA Knowledge Ltd | 7Safe Training

Attribute 0x30 $FILE_NAME

The File Name attribute contains the actual file name itself together with the logical size (true size of file) and physical size (size of the file on the file system) of the file.

This attribute is known as a resident attribute meaning that all the relevant file information only resides within the attribute itself.

An example of a File Name attribute is detailed below:

Screenshot of $MFT file segment entry attribute 0x30.

Note this attribute also contains the files parent ID (the folder it resides in) and another set of dates and times referred to as the secondary MAC times which are not displayed to a user. On viewing the File Name attribute you will note the name of the file is ‘Autoruns.csv’.

Additional information…

The creation date and time of both the primary and secondary MAC times must always be identical. If the primary date different to the secondary date creation date is typical of a files dates and times being tampered with. The file will therefore require a closer inspection to determine its provenance.

© PA Knowledge Ltd | 7Safe Training
This article is from the free online

Introduction to Digital Forensics: Malware Analysis and Investigations

Created by
FutureLearn - Learning For Life

Our purpose is to transform access to education.

We offer a diverse selection of courses from leading universities and cultural institutions from around the world. These are delivered one step at a time, and are accessible on mobile, tablet and desktop, so you can fit learning around your life.

We believe learning should be an enjoyable, social experience, so our courses offer the opportunity to discuss what you’re learning with others as you go, helping you make fresh discoveries and form new ideas.
You can unlock new opportunities with unlimited access to hundreds of online short courses for a year by subscribing to our Unlimited package. Build your knowledge with top universities and organisations.

Learn more about how FutureLearn is transforming access to education