$LogFile Parsers Compared: LogFileParser, NTFS Log Tracker
A factual comparison of NTFS $LogFile tools: LogFileParser, NTFS Log Tracker, TZWorks mala, dfir_ntfs, ntfstool, MFTECmd and a browser parser. When to use each.
A factual comparison of NTFS $LogFile tools: LogFileParser, NTFS Log Tracker, TZWorks mala, dfir_ntfs, ntfstool, MFTECmd and a browser parser. When to use each.
NTFS $LogFile retention in practice and its other blind spots: no clock, missing names, metadata only, rewritten by chkdsk or ntfs-3g, parsers that disagree.
A fictional intrusion on FIN-WKS-07 worked end to end from the NTFS $LogFile: rogue account, toolkit, backdated binary, rclone, a deleted note, and the report.
Inside the NTFS $LogFile restart pages: restart area fields, the NTFS client record, checkpoints, and how to turn a log sequence number into a file offset.
NTFS log format 1.1 and 2.0 side by side: tail pages vs 32 fast pages, where the circular area starts, why live captures show 2.0, and what parsers must do.
What the NTFS $LogFile keeps after a deletion: name, folder, MFT entry, times, sizes, data runs, sometimes content. How to find it and what it cannot prove.
How $LogFile exposes timestomping: $STANDARD_INFORMATION before and after values, $SI vs $FN checks, four practical tells, false positives, and how to confirm.
The NTFS log record header byte by byte, the 38 redo/undo opcodes, which ones matter in forensics, and how create, delete, rename and timestamp changes look.
A practical walkthrough: load $LogFile and $MFT in a browser parser, read the log header, triage flagged events, check raw redo/undo bytes and export results.
Copy the locked NTFS $LogFile and its $MFT: KAPE, Velociraptor, FTK Imager, RawCopy, icat and ntfscat commands, plus checks that prove the copy is usable.
$LogFile, $UsnJrnl:$J and $MFT compared from the transaction log's side: what each records, how far back it goes, what only $LogFile proves, how to join them.
What the NTFS $LogFile records, how its pages and redo/undo records work, what it proves in an investigation, how to collect it and where it stops.