Get the latest tech news

Going beneath NTFS: USN Journal, dfir_NTFS, and artefact-driven investigations


A practical deep dive into NTFS forensic artefacts: MFT, USN Journal, $LogFile, and how to combine them with dfir_ntfs and MFTECmd to detect anti-forensic techniques.

None

Get the Android app

Or read this on Hacker News

Read more on:

Photo of USN Journal

USN Journal

Photo of dfir_NTFS

dfir_NTFS

Photo of artefact

artefact