Going beneath NTFS: USN Journal, dfir_NTFS, and artefact-driven investigations

·Hacker News··

A practical deep dive into NTFS forensic artefacts: MFT, USN Journal, $LogFile, and how to combine them with dfir_ntfs and MFTECmd to detect anti-forensic techniques.

Read full article →

Related Articles

GCC steering committee announces AI policy
arto · Hacker News · 5h ago
Why Is Everyone Trying to Build a Solid-State Battery?
crescit_eundo · Hacker News · 4h ago
AI's top startups are barely publishing their research
YeGoblynQueenne · Hacker News · 19h ago
Why Don't People Use Formal Methods? (2019)
Thom2503 · Hacker News · 4h ago
Document-borne AI worms can self-propagate through Copilot for Word
Canopy9560 · Hacker News · 1d ago