<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>NTFS $LogFile Parser — Blog</title>
    <link>https://www.logfileparser.com/de/blog</link>
    <description>Latest from Blog</description>
    <language>de</language>
    <lastBuildDate>Sun, 27 Sep 2026 20:44:11 GMT</lastBuildDate>
    <atom:link href="https://www.logfileparser.com/de/blog/feed.xml" rel="self" type="application/rss+xml"/>
    <item>
      <title>$LogFile-Parser-Vergleich: LogFileParser, NTFS Log Tracker</title>
      <link>https://www.logfileparser.com/de/blog/logfile-parser-comparison</link>
      <guid isPermaLink="true">https://www.logfileparser.com/de/blog/logfile-parser-comparison</guid>
      <description>Sachlicher Vergleich von NTFS-$LogFile-Tools: LogFileParser, NTFS Log Tracker, TZWorks mala, dfir_ntfs, ntfstool, MFTECmd, Browser-Parser. Wann welches passt.</description>
      <author>Florian Amette</author>
      <pubDate>Sun, 27 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Wie weit reicht das $LogFile zurück? Grenzen und Fallstricke</title>
      <link>https://www.logfileparser.com/de/blog/logfile-limitations</link>
      <guid isPermaLink="true">https://www.logfileparser.com/de/blog/logfile-limitations</guid>
      <description>Wie lange das NTFS-$LogFile reicht, und seine blinden Flecken: keine Uhr, fehlende Namen, nur Metadaten, von chkdsk oder ntfs-3g überschrieben, Parser uneins.</description>
      <author>Florian Amette</author>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Eine $LogFile-Untersuchung Schritt für Schritt (fiktiv)</title>
      <link>https://www.logfileparser.com/de/blog/logfile-investigation-walkthrough</link>
      <guid isPermaLink="true">https://www.logfileparser.com/de/blog/logfile-investigation-walkthrough</guid>
      <description>Ein fiktiver Einbruch auf FIN-WKS-07, ganz aus dem NTFS-$LogFile ermittelt: fremdes Konto, Toolkit, rückdatierte Binärdatei, rclone, gelöschte Notiz.</description>
      <author>Florian Amette</author>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Restart Area und LSN im $LogFile erklärt</title>
      <link>https://www.logfileparser.com/de/blog/logfile-restart-area-lsn</link>
      <guid isPermaLink="true">https://www.logfileparser.com/de/blog/logfile-restart-area-lsn</guid>
      <description>Ein Blick in die Restart-Seiten des NTFS-$LogFile: Felder der Restart Area, Client-Record von NTFS, Checkpoints – und wie aus einer LSN ein Datei-Offset wird.</description>
      <author>Florian Amette</author>
      <pubDate>Sat, 19 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>$LogFile-Format 1.1 vs. 2.0: was sich mit Windows 8 ändert</title>
      <link>https://www.logfileparser.com/de/blog/logfile-version-1-1-vs-2-0</link>
      <guid isPermaLink="true">https://www.logfileparser.com/de/blog/logfile-version-1-1-vs-2-0</guid>
      <description>NTFS-Logformat 1.1 und 2.0 im Vergleich: Tail Pages vs. 32 Fast Pages, Start des zirkulären Bereichs, warum Live-Sicherungen 2.0 zeigen, was Parser tun müssen.</description>
      <author>Florian Amette</author>
      <pubDate>Thu, 17 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Spuren gelöschter Dateien im $LogFile finden</title>
      <link>https://www.logfileparser.com/de/blog/logfile-deleted-files-evidence</link>
      <guid isPermaLink="true">https://www.logfileparser.com/de/blog/logfile-deleted-files-evidence</guid>
      <description>Was das NTFS-$LogFile nach einer Löschung behält: Name, Ordner, MFT-Eintrag, Zeiten, Größen, Data Runs, teils Inhalt. Wie man es findet, was es nicht beweist.</description>
      <author>Florian Amette</author>
      <pubDate>Tue, 15 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Timestomping mit dem NTFS-$LogFile erkennen</title>
      <link>https://www.logfileparser.com/de/blog/detect-timestomping-logfile</link>
      <guid isPermaLink="true">https://www.logfileparser.com/de/blog/detect-timestomping-logfile</guid>
      <description>Wie das $LogFile Timestomping sichtbar macht: $STANDARD_INFORMATION vorher/nachher, $SI-/$FN-Vergleich, vier Indizien, Fehlalarme und wie man Befunde bestätigt.</description>
      <author>Florian Amette</author>
      <pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Redo- und Undo-Operationen im NTFS-$LogFile erklärt</title>
      <link>https://www.logfileparser.com/de/blog/logfile-redo-undo-operations</link>
      <guid isPermaLink="true">https://www.logfileparser.com/de/blog/logfile-redo-undo-operations</guid>
      <description>Der NTFS-Log-Header Byte für Byte, die 38 Redo-/Undo-Opcodes, welche forensisch zählen und wie Anlegen, Löschen, Umbenennen und Zeitstempeländerungen aussehen.</description>
      <author>Florian Amette</author>
      <pubDate>Thu, 10 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Ein NTFS-$LogFile Schritt für Schritt analysieren</title>
      <link>https://www.logfileparser.com/de/blog/how-to-analyze-ntfs-logfile</link>
      <guid isPermaLink="true">https://www.logfileparser.com/de/blog/how-to-analyze-ntfs-logfile</guid>
      <description>Praxisanleitung: $LogFile und $MFT in einen Browser-Parser laden, den Log-Header lesen, markierte Ereignisse sichten, Redo-/Undo-Bytes prüfen und exportieren.</description>
      <author>Florian Amette</author>
      <pubDate>Tue, 08 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Das NTFS-$LogFile sichern: live und post mortem</title>
      <link>https://www.logfileparser.com/de/blog/acquire-ntfs-logfile</link>
      <guid isPermaLink="true">https://www.logfileparser.com/de/blog/acquire-ntfs-logfile</guid>
      <description>Das gesperrte NTFS-$LogFile samt $MFT kopieren: Befehle für KAPE, Velociraptor, FTK Imager, RawCopy, icat und ntfscat sowie Prüfungen, ob die Kopie taugt.</description>
      <author>Florian Amette</author>
      <pubDate>Sat, 05 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>$LogFile, $UsnJrnl oder $MFT: welches NTFS-Artefakt wann</title>
      <link>https://www.logfileparser.com/de/blog/logfile-vs-usnjrnl-vs-mft</link>
      <guid isPermaLink="true">https://www.logfileparser.com/de/blog/logfile-vs-usnjrnl-vs-mft</guid>
      <description>$LogFile, $UsnJrnl:$J und $MFT aus Sicht des Transaktionslogs: was jedes erfasst, wie weit es zurückreicht, was nur das $LogFile belegt, wie man sie verknüpft.</description>
      <author>Florian Amette</author>
      <pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>NTFS-$LogFile-Forensik: der vollständige Leitfaden</title>
      <link>https://www.logfileparser.com/de/blog/ntfs-logfile-forensics-guide</link>
      <guid isPermaLink="true">https://www.logfileparser.com/de/blog/ntfs-logfile-forensics-guide</guid>
      <description>Was das NTFS-$LogFile protokolliert, wie Seiten und Redo-/Undo-Einträge aufgebaut sind, was es in Ermittlungen belegt, wie man es sichert und wo es endet.</description>
      <author>Florian Amette</author>
      <pubDate>Tue, 01 Sep 2026 00:00:00 GMT</pubDate>
    </item>
  </channel>
</rss>