Deep Dive into NTFS USN Journal for Digital Forensics Investigations
A technical article published on July 6, 2026, explores the use of the NTFS USN (Update Sequence Number) Journal as a forensic artefact in digital investigations. The piece focuses on the open-source tool dfir_NTFS and how it can be leveraged to extract and analyse file system activity records. The USN Journal, a feature built into the NTFS file system, logs changes to files and directories, making it valuable for incident response and forensic work. The article takes an artefact-driven approach, guiding investigators on how to uncover evidence of file creation, modification, and deletion. It was shared on Hacker News, where it received a small number of points and minimal discussion.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in