
Sign up to save your podcasts
Or
The $UsnJrnl is an artifact that logs certain changes to files in NTFS volumes. It is a great source of timeline information for malware\ IR investigations, time stomping concerns and anti-forensics activities (i.e. wiping) as well as an additional source of file use and knowledge evidence for disk forensics.
4.9
6161 ratings
The $UsnJrnl is an artifact that logs certain changes to files in NTFS volumes. It is a great source of timeline information for malware\ IR investigations, time stomping concerns and anti-forensics activities (i.e. wiping) as well as an additional source of file use and knowledge evidence for disk forensics.
361 Listeners
627 Listeners
363 Listeners
183 Listeners
1,003 Listeners
311 Listeners
399 Listeners
7,875 Listeners
187 Listeners
314 Listeners
6 Listeners
129 Listeners
33 Listeners
158 Listeners
14 Listeners