Possible to dump th...
 
Notifications
Clear all

Possible to dump the $MFT/USN using CLI Tools?

2 Posts
2 Users
0 Reactions
649 Views
(@jaysp)
Active Member
Joined: 15 years ago
Posts: 13
Topic starter  

I am interested in dumping the $MFT/NTFS USN Change Journal to a text file, to analyze malware. The only tools I know of that will do so require an image. Does anyone here know of a CL tool that will do so, preferably FOSS (intended for use in a commercial environment)?

Thanks.


   
Quote
(@douglasbrush)
Prominent Member
Joined: 16 years ago
Posts: 812
 

Might want to give MFT Ripper a try.


   
ReplyQuote
Share: