Computer Hacking Forensic Investigator (CHFI v10) — Question 222
Which following forensic tool allows investigator to detect and extract hidden streams on NTFS drive?
Answer options
- A. Autopsy
- B. TimeStomp
- C. analyzeMFT
- D. Stream Detector
Correct answer: D
Explanation
Stream Detector is specifically designed to identify and extract hidden data streams on NTFS file systems, making it the correct choice. While Autopsy, TimeStomp, and analyzeMFT are valuable forensic tools, they do not focus on the detection of hidden streams in the same way that Stream Detector does.