ReFS Reference

Examples

Worked, end-to-end forensic walkthroughs.

Decode a ReFS VBR by HandDecode a ReFS VBR by Hand# Goal: Read every field of a ReFS Volume Boot Record straight out of a raw hexdump – no parser – and derive cluster size, container …
Identify a Native vs Upgraded ReFS VolumeIdentify a Native vs Upgraded ReFS Volume# Goal: Decide whether a v3.14 ReFS volume was freshly formatted under Win11 24H2 or upgraded from an older v3.4 volume. Both …
Worked Example: Detecting a Back-Dated (Timestomped) FileWorked Example: Detecting a Back-Dated (Timestomped) File# Goal: take a ReFS image, find the files whose creation time was forged into the past, and prove the tampering …
Worked Example: Enumerate Every Name of One Physical File (a Hard-Link Group)Worked Example: Enumerate Every Name of One Physical File (a Hard-Link Group)# Goal: given a ReFS image, recover the complete list of names that point at one physical …
Worked Example: Recover a Deleted File from a ReFS ImageWorked Example: Recover a Deleted File from a ReFS Image# Goal: run every available ReFS deletion-recovery method against one real image and read the results honestly — …