Several more bugfixes and added features have been implemented lately. Some of the more interesting changes;
Added option to configure if source is from Nt5.x (XP,2003), which would improve parsing.
Added decode of UpdateRecordDataRoot and UpdateRecordDataAllocation.
Added decode of $Reparse$R.
Added option to extract resident attribute updates.
great tool thanks o lot
Another important update with v2.0.0.7. Implemented a much improved filename identification feature. The processing time has increased slightly, but the output quality is much higher. Also fixed a bug that was introduced in 2.0.0.4 that caused certain $UsnJrnl transactions to not be identified.
Hi,
Windows 10 is using new undo/redo operation codes (0x23-0x25). What do they mean ?
Regards
I don't know so will have to analyze it. Thanks for notifying.
I am unable to find these codes in my $LogFile. Would you be able to share a sample $LogFile with me with such codes in?
Commandline mode also implemented for this tool too, among other nice improvements and bugfixes.