Going beneath NTFS: USN Journal, dfir_NTFS, and artefact-driven investigations
tech
Hacker News is featuring a technical analysis of NTFS forensics that explores the USN Journal and artefact-driven investigation methods using dfir-NTFS to extract evidence from Windows filesystem structures.
Source: https://andreafortuna.org/2026/07/06/ntfs-forensics-deep-dive/
Listen to this story
Hear this and more stories in a personalized audio briefing.
Open The Chonkerton