Quantcast
Channel: DFIR Training - Recently Added Listings
Viewing all articles
Browse latest Browse all 888

NTFS Log Tracker

$
0
0
This tool can parse $LogFile, $UsnJrnl of NTFS.
A input of this tool is sample file extracted by another tool like Encase, Winhex.
If you want to see "Full Path" information, you should input $MFT file.
A time information is local time.(system's time)

Category: Forensic Utilities - Windows
Category URL: http://www.dfir.training/component/mtree/forensic-utilities-windows?Itemid=

Viewing all articles
Browse latest Browse all 888

Trending Articles