Going beneath NTFS: USN Journal, dfir_NTFS, and artefact-driven investigations

·Hacker News··

A practical deep dive into NTFS forensic artefacts: MFT, USN Journal, $LogFile, and how to combine them with dfir_ntfs and MFTECmd to detect anti-forensic techniques.

Read full article →

Related Articles

Revolut confirms customer data breach through fake government requests
tdrz · Hacker News · 9h ago
google.com/goto: Google's anti-scraping update
1e1a · Hacker News · 1d ago
Will there be a 7G?
Betelbuddy · Hacker News · 1d ago
Real-SWE: Benchmarking AI models on private, real-world, enterprise codebases
theanonymousone · Hacker News · 22h ago
After Math
throwaway81523 · Hacker News · 16h ago