πŸ“˜
DFIR
search
⌘Ctrlk
πŸ“˜
DFIR
  • Networking
    • Networking
  • Windows
    • Administration
    • Forensics
      • System Info
      • Memory
      • Network Logs
      • File System
        • Mounting File Systems
        • Log2Timeline
        • Volume Shadow Copies
        • $I30
        • UsnJournal/$LogFile
        • MFT
        • NTFS
        • Shellbags
        • Recycle Bin
      • Registry
      • Network Share
      • Exfiltration
      • Evidence of Execution
      • Hacktool Artifacts
      • Event Logs
      • 3rd Party Apps
      • Example Page
    • Cheat Sheet
    • Investigation
    • Internals
    • Active Directory
    • MISC
  • Linux
    • Forensics
    • SSH
    • Linux WebShells
    • Directories of Interest
    • Internals
  • Enterprise Architecture
    • CI/CD Pipline
    • Citrix
    • Web Applications
    • The Cloud
    • vSphere
    • Containers
    • Troubleshooting
  • Mac
    • Forensics
  • Attacker Information
    • Adversary Operations
    • Actor Playbooks
    • Abused Domains
  • IR Playbook
    • Activity from Unmanaged Host
    • Recommendations
  • Reverse Engineering
    • Python - Pyinstaller
gitbookPowered by GitBook
block-quoteOn this pagechevron-down
  1. Windowschevron-right
  2. Forensicschevron-right
  3. File System

UsnJournal/$LogFile

https://www.otorio.com/resources/usnjrnl-extraction-for-efficient-investigation/www.otorio.comchevron-right
LogoDFIR-02 : Journal Forensics | Cyb3rSn0rlaxwww.unh4ck.comchevron-right

File Location:

hashtag
Parse Data

hashtag
Considerations

hashtag
Anti-Forensics

Previous$I30chevron-leftNextMFTchevron-right

Last updated 2 years ago

  • Parse Data
  • Considerations
  • Anti-Forensics