DFSP # 015 - $UsnJrnl File

DFSP # 015 - $UsnJrnl File

The $UsnJrnl is an artifact that logs certain changes to files in NTFS volumes. It is a great source of timeline information for malware\ IR investigations, time stomping concerns and anti-forensics activities (i.e. wiping) as well as an additional source of file use and knowledge evidence for disk forensics.

Denne episoden er hentet fra en åpen RSS-feed og er ikke publisert av Podme. Den kan derfor inneholde annonser.

Episoder(498)

Populært innen Vitenskap

fastlegen
tingenes-tilstand
jss
forskningno
sinnsyn
villmarksliv
liberal-halvtime
rss-paradigmepodden
rekommandert
tomprat-med-gunnar-tjomlid
fjellsportpodden
dekodet-2
aldring-og-helse-podden
rss-rekommandert
rss-inn-til-kjernen-med-sunniva-rose
diagnose
vett-og-vitenskap-med-gaute-einevoll
kvinnehelsepodden
rss-overskuddsliv
hva-er-greia-med