NTFS Log Tracker

NTFS Log Tracker

This tool can parse $LogFile, $UsnJrnl of NTFS.
A input of this tool is sample file extracted by another tool like Encase, Winhex.
If you want to see "Full Path" information, you should input $MFT file.
A time information is local time.(system's time)


Parsed $LogFile Event
  • Creating File/Directory(including "File System Tunneling")
  • Writing Resident/NonResident Data
    • Writing Resident Data : "Data offset" means the location of Resident Data within $LogFile.
    • Writing Non-Resident Data : "Cluster Number" means "StartClusterNumber(Allocated Cluster Count)" of Non-Resident Data within volume.
  • Deleting File/Directory
  • Renaming File/Directory
  • Moving File/Directory


Parsed $UsnJrnl Event
  • Event Info : http://msdn.microsoft.com/en-us/library/aa365722.aspx 
  • File Attribute : http://msdn.microsoft.com/en-us/library/gg258117.aspx


User Interface



Update History
  • v1.41
    • The bug of parsing $LogFile(Win10) is fixed.
    • The Command Line Version is developed.
  • v1.4
    • $UsnJrnl record carving function is added
    • Search function is changed.(to only selected columns)
    • Non-English keyword search is supported. 
    • Tab bug is fixed.
  • v1.32
    • The bug of parsing $LogFile is fixed.
  • v1.31
    • The bug of parsing $LogFile is fixed.
  • v1.3
    • The bug of parsing $UsnJrnl is fixed.
  • v1.2
    • The bug of parsing $LogFile is fixed.
  • v1.1
    • Resizing bug is fixed.
    • The bug of Renaming Event is fixed.(the event of renaming long file name was not extracted.)
    • USN_RECORD_V3 is supported.(But in this case, Full Path Information is not supported.)
  • v1.0
    • Full screen mode is supported.
    • Additional information is supported in $LogFile Tab.
      • The "File System Tunneling" Event
      • The target file information on "Writing Data" event
      • The event time on "Deleting File/Directory" and "Renaming File/Directory" event
      • The "Moving File/Directory" event and it's event time
    • The "Source Info" column is added in $UsnJrnl Tab
  • v0.95
    • "Search Result" Tab is added.
    • Progress bar is added.
    • The parsed data is saved to SQLite DB.(for Massive Data)
  • v0.9
    • Initial version

Created by Junghoon Oh(blueangel)
Email : blueangel1275@gmail.com
ċ
NTFS Log Tracker CMD v1.41.zip
(1075k)
Junghoon Oh,
2016. 8. 25. 오전 8:14
ċ
NTFS Log Tracker v1.41.zip
(1190k)
Junghoon Oh,
2016. 9. 10. 오전 2:49
Ċ
Junghoon Oh,
2015. 1. 25. 오후 10:00
Ċ
Junghoon Oh,
2015. 1. 25. 오후 10:00
Ċ
Junghoon Oh,
2015. 3. 9. 오전 5:20
Ċ
Junghoon Oh,
2015. 3. 9. 오전 5:20
Ċ
Junghoon Oh,
2013. 8. 4. 오전 6:07
Ċ
Junghoon Oh,
2013. 8. 4. 오전 6:07
Comments