NTFS Log Tracker

NTFS Log Tracker

This tool can parse $LogFile, $UsnJrnl of NTFS.
A input of this tool is sample file extracted by another tool like Encase, Winhex.
If you want to see "Full Path" information, you should input $MFT file.
A time information is local time.(system's time)


Parsed $LogFile Event
  • Creating File/Directory(including "File System Tunneling")
  • Writing Resident/NonResident Data
    • Writing Resident Data : "Data offset" means the location of Resident Data within $LogFile.
    • Writing Non-Resident Data : "Cluster Number" means "StartClusterNumber(Allocated Cluster Count)" of Non-Resident Data within volume.
  • Deleting File/Directory
  • Renaming File/Directory
  • Moving File/Directory


Parsed $UsnJrnl Event
  • Event Info : http://msdn.microsoft.com/en-us/library/aa365722.aspx 
  • File Attribute : http://msdn.microsoft.com/en-us/library/gg258117.aspx


User Interface



Update History
  • v1.5
    • The Selection function of Timezone(UTC) is added.
    • The Applying DST(Daylight Saving Time) is supported.
    • UsnJrnl Event info is changed.
      • File_Added -> Data_Added
      • File_Truncated -> Data_Truncated
    • The speed of exporting CSV file is improved.
    • The bug of initialzing UsnJrnl peroid combo box is fixed.
  • v1.41
    • The bug of parsing $LogFile(Win10) is fixed.
    • The Command Line Version is developed.
  • v1.4
    • $UsnJrnl record carving function is added
    • Search function is changed.(to only selected columns)
    • Non-English keyword search is supported. 
    • Tab bug is fixed.
  • v1.32
    • The bug of parsing $LogFile is fixed.
  • v1.31
    • The bug of parsing $LogFile is fixed.
  • v1.3
    • The bug of parsing $UsnJrnl is fixed.
  • v1.2
    • The bug of parsing $LogFile is fixed.
  • v1.1
    • Resizing bug is fixed.
    • The bug of Renaming Event is fixed.(the event of renaming long file name was not extracted.)
    • USN_RECORD_V3 is supported.(But in this case, Full Path Information is not supported.)
  • v1.0
    • Full screen mode is supported.
    • Additional information is supported in $LogFile Tab.
      • The "File System Tunneling" Event
      • The target file information on "Writing Data" event
      • The event time on "Deleting File/Directory" and "Renaming File/Directory" event
      • The "Moving File/Directory" event and it's event time
    • The "Source Info" column is added in $UsnJrnl Tab
  • v0.95
    • "Search Result" Tab is added.
    • Progress bar is added.
    • The parsed data is saved to SQLite DB.(for Massive Data)
  • v0.9
    • Initial version

Created by Junghoon Oh(blueangel)
Email : blueangel1275@gmail.com
ċ
NTFS Log Tracker v1.5 CMD.zip
(1048k)
Junghoon Oh,
2018. 7. 20. 오전 1:31
ċ
NTFS Log Tracker v1.5.zip
(1162k)
Junghoon Oh,
2018. 7. 20. 오전 1:31
Ċ
Junghoon Oh,
2018. 7. 20. 오전 1:31
Ċ
Junghoon Oh,
2018. 7. 20. 오전 1:31
Ċ
Junghoon Oh,
2015. 3. 9. 오전 5:20
Ċ
Junghoon Oh,
2015. 3. 9. 오전 5:20
Ċ
Junghoon Oh,
2018. 5. 30. 오전 7:09
Ċ
Junghoon Oh,
2013. 8. 4. 오전 6:07
Comments