Information | comment |
---|---|
drive/partition | *nix notation (/dev/hda or /dev/sda) |
file name | |
size | Bytes |
contents of the stream | determined by the file command (stat + magic number test) |
last access date/time | atime |
last modification date/time | mtime |
feature\program | streams (sysinternals/msft) | lads | ntfs-ads |
list | |||
delete all streams | |||
delete individual streams | |||
copy/extract | |||
determine contents | |||
show atime | |||
show mtime | |||
cannot be cheated by windows rootkits? | |||
no change atime? | |||
show national characters correctly? (üöäøщξ) | * | ||
open source? | ** |
echo X5O!P%@AP[4\PZX54(P^)7CC)7}$EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H* > c:\test.txt:eicar.com