Windows USN Journal...
 
Notifications
Clear all

Windows USN Journal Parsing

1 Posts
1 Users
0 Reactions
1,945 Views
(@gorvq7222)
Reputable Member
Joined: 11 years ago
Posts: 236
Topic starter  

What is "USN Journal"? It is "Update Sequence Number Journal". It records changes in the NTFS volume. The scenario is about Bomb threat. I use X-Ways Forensics to parse USN Journal and you guys could take a look at my blog to see the parsing result. You could see the column name - "Timestamp","Change type","File ID","Attribue" and "Filename".
http//www.cnblogs.com/pieces0310/p/4970250.html

Where is USN Journal? That's it. A strange file whose name is $USNJml$J. What is $J? It is so called ADS(Alternate Data Stream). Usually ADS will contain metadata of that file.

Let's take the first reocrd in the screenshot for examplie. The file "炸彈製作.lnk" created means suspect did double click the folder "炸彈製作" and the timestamp was 2013/12/16 215041. The other records also had something to do with "Bomb" at 2013/12/16 2150. So we could know that suspect did access those folders and files that time, and no doubt those files and folders did exist at that time. Look into USN parsing result and we could get a whole picture of "Timeline".


   
Quote
Share: