Going beneath NTFS: USN Journal, dfir_NTFS, and artefact-driven investigations
A practical deep dive into NTFS forensic artefacts: MFT, USN Journal, $LogFile, and how to combine them with dfir_ntfs and MFTECmd to detect anti-forensic techniques.
Read full article →