file guid partition system table forensics...
TRANSCRIPT
FileSystemForensics
THINK BIG WE DO
U R Ihttp://www.forensics.cs.uri.edu
Digital Forensics CenterDepartment of Computer Science and Statics
GUID Partition Table
Partitioning
GUID Partition Table
Partitioning
GPT PartitioningGUID Partition Table- Used on Intel IA64 (EFI) Systems- Supports up to 128 Partitions- 64-bit (8 byte) LBA addressing
GUID (Globally Unique Identifier)- Uses 128-bit unique identifiers for- Partition Type- Partition Identifier
Required for Boot Partitions- Microsoft Windows on an EFI System- Mac OS X
GPT PartitioningProtective MBR- Allows compatibility with older systems- Single MBR Partition of type 0xEEPrimary GPT Header- General Layout of the diskPartition Entries- Description of Each PartitionPartition AreaBackup Partition EntriesSecondary GPT Header- Backup Copies- Last Sectors of Disk
Protective MBR
Primary GPT Header
Partition Entries
Partition 1
Partition 2
. . .Other Partitions
. . .
Secondary Partition Entries
Secondary GPT Header
012
34
End of Disk (EOD)EOD-1
EOD-33
GPT PartitioningProtective MBR
Primary GPT Header
Partition Entries
Partition 1
Partition 2
. . .Other Partitions
. . .
Secondary Partition Entries
Secondary GPT Header
012
34
(EOD)EOD-1
EOD-33
Decimal Hex Primary GPT Header0 00 Signature “EFI PART”8 08 Version12 0C GPT Size in Bytes (92)16 10 CRC32 Checksum of GPT Header20 14 Reserved24 18 LBA of Current GPT Structure32 20 LBA of Other GPT Structure40 28 Start LBA of Partition Area48 30 End LBA of Partition Area56 38 Disk GUID72 48 Start LBA of Partition Entries80 50 Number of Entries in Partition Table 84 54 Size of Each Partition Table Entry88 58 CRC32 Checksum of Partition Table92 5C Reserved
Primary GPT Header
GPT PartitioningProtective MBR
Primary GPT Header
Partition Entries
Partition 1
Partition 2
. . .Other Partitions
. . .
Secondary Partition Entries
Secondary GPT Header
012
34
(EOD)EOD-1
EOD-33
Decimal Hex Partition Entry in Partition Table (128 bytes)0 00 Partition Type GUID (128-bits)16 10 Unique Partition GUID (128-bits)32 20 Starting LBA of Partition40 28 Ending LBA of Partition48 30 Partition Attributes56 38 Partition Name in Unicode
Partition Entries
Microsoft Windows limits the number of partition
table entries to 128.
32 sectors = 128 entries ÷ 4 entries per sector
THINK BIG WE DO
U R Ihttp://www.forensics.cs.uri.edu
Digital Forensics CenterDepartment of Computer Science and Statics
GUID Partition Table Partitioning
GUID Partition Table Partitioning