ReFS Forensics Reference

Format support

Verified means a measurement was made on an image of that format and recorded with the claim. It is deliberately a floor: a statement can be true of a format nobody here has an image of, and this table will not say so. Nothing is inferred from what a claim asserts — only from what was checked.

Which ReFS formats each area of this project has been verified on — not which formats a statement is about. A claim can describe a format that no image here was ever checked against; this table counts only measurements actually made, so it is a floor, not a ceiling.

A number is how many verified statements in that area cover that format. Blank means nothing in that area was checked on it — which is a gap in the evidence, not a statement that ReFS differs.

Area3.43.73.93.103.143.15insiderscope not recorded
File records & attributes559777321124
Journals & log48315428
B+-tree structure44747451224
Object & container tables39112371111
Boot & volume331133963
Checkpoints271832
Other41810
Security & links8212054
Architecture & driver12114
Deletion & recovery364
Snapshots & CoW80

74 statements have no recorded verification scope. They are counted in the last column rather than dropped: leaving them out would make coverage look strongest exactly where it is least documented. Most are older entries whose record kept the date of the check but not the volumes it ran on.

Formats 3.11 to 3.13 appear nowhere because no image of them exists in this project’s corpus. A boundary such as “this applies from 3.11” is a statement about where behaviour changes, not a measurement taken there.