Difference between pages "KnTTools" and "Windows SuperFetch Format"

From Forensics Wiki
(Difference between pages)
Jump to: navigation, search
(updated external links)
 
(File header)
 
Line 1: Line 1:
{{Expand}}
+
{{expand}}
  
KnTTools, developed by [[GMG Systems Inc.]] is a suite of command-line tools designed for [[Windows]] [[Tools:Memory Imaging|memory acquisition]] and [[Windows Memory Analysis|memory analysis]]. One of the components of KnTTools, [[KnTList]], was used in the 2005 [[Digital Forensic Research Workshop|DFRWS]] Memory Analysis Challenge. Another tool, [[Kntdd]], can be used to image physical memory.
+
== MEMO file ==
 +
Some of the <tt>Ag*.db</tt> files are MEMO files.
  
There are two versions of the suite, Basic and Enterprise editions.
+
The MEMO file consists of:
 +
* file header
 +
* compressed blocks
  
The programs are sold with a separate End User License Agreement (EULA) for each program.
+
=== File header ===
 +
The file header is 84 bytes of size and consists of:
 +
{| class="wikitable"
 +
|-
 +
! Offset
 +
! Size
 +
! Value
 +
! Description
 +
|-
 +
| 0
 +
| 4
 +
| 0x304D454D ("MEM0") or 0x4F4D454D ("MEMO")
 +
| Signature
 +
|-
 +
| 4
 +
| 4
 +
|
 +
| Uncompressed (total) data size
 +
|-
 +
|}
 +
 
 +
=== Compressed blocks ===
 +
The file header is followed by compressed blocks:
 +
{| class="wikitable"
 +
|-
 +
! Offset
 +
! Size
 +
! Value
 +
! Description
 +
|-
 +
| 0
 +
| 4
 +
|
 +
| Compressed data size
 +
|-
 +
| 4
 +
| ...
 +
|
 +
| Compressed data
 +
|-
 +
|}
 +
 
 +
=== Uncompressed data ===
 +
<b>TODO</b>
 +
 
 +
== TRX file ==
 +
The <tt>Ag*.db.trx</tt> files are TRX files.
 +
 
 +
<b>Note that the following format specification is incomplete.</b>
 +
 
 +
=== File header ===
 +
The file header is 84 bytes of size and consists of:
 +
{| class="wikitable"
 +
|-
 +
! Offset
 +
! Size
 +
! Value
 +
! Description
 +
|-
 +
| 0
 +
| 4
 +
| 1
 +
| Unknown (Version?)
 +
|-
 +
| 4
 +
| 4
 +
|
 +
| Unknown
 +
|-
 +
| 8
 +
| 4
 +
|
 +
| File size
 +
|-
 +
| 12
 +
| 4
 +
|
 +
| Unknown (Record count?)
 +
|-
 +
| 16
 +
| 4
 +
|
 +
| Unknown (Record count?)
 +
|-
 +
| 20
 +
| 4
 +
|
 +
| Unknown (Records offset or file header size)
 +
|-
 +
|}
 +
 
 +
== See Also ==
 +
* [[SuperFetch]]
  
 
== External Links ==
 
== External Links ==
 +
* [http://blog.rewolf.pl/blog/?p=214 Windows SuperFetch file format – partial specification], by ReWolf, October 5, 2011
  
* [http://www.gmgsystemsinc.com/knttools/ Official website]
+
[[Category:File Formats]]
* [http://www.gmgsystemsinc.com/knttools/KnTTools_NI_END_USER_LICENSE_AGREEMENT.txt KnTTools EULA]
+
* [http://www.gmgsystemsinc.com/knttools/KnTList_NI_END_USER_LICENSE_AGREEMENT.txt KnTList EULA]
+

Revision as of 00:28, 15 April 2014

Information icon.png

Please help to improve this article by expanding it.
Further information might be found on the discussion page.

Contents

MEMO file

Some of the Ag*.db files are MEMO files.

The MEMO file consists of:

  • file header
  • compressed blocks

File header

The file header is 84 bytes of size and consists of:

Offset Size Value Description
0 4 0x304D454D ("MEM0") or 0x4F4D454D ("MEMO") Signature
4 4 Uncompressed (total) data size

Compressed blocks

The file header is followed by compressed blocks:

Offset Size Value Description
0 4 Compressed data size
4 ... Compressed data

Uncompressed data

TODO

TRX file

The Ag*.db.trx files are TRX files.

Note that the following format specification is incomplete.

File header

The file header is 84 bytes of size and consists of:

Offset Size Value Description
0 4 1 Unknown (Version?)
4 4 Unknown
8 4 File size
12 4 Unknown (Record count?)
16 4 Unknown (Record count?)
20 4 Unknown (Records offset or file header size)

See Also

External Links