<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>NTFS $LogFile Parser — Blog</title>
    <link>https://www.logfileparser.com/en/blog</link>
    <description>Latest from Blog</description>
    <language>en</language>
    <lastBuildDate>Sun, 27 Sep 2026 20:44:11 GMT</lastBuildDate>
    <atom:link href="https://www.logfileparser.com/en/blog/feed.xml" rel="self" type="application/rss+xml"/>
    <item>
      <title>$LogFile Parsers Compared: LogFileParser, NTFS Log Tracker</title>
      <link>https://www.logfileparser.com/en/blog/logfile-parser-comparison</link>
      <guid isPermaLink="true">https://www.logfileparser.com/en/blog/logfile-parser-comparison</guid>
      <description>A factual comparison of NTFS $LogFile tools: LogFileParser, NTFS Log Tracker, TZWorks mala, dfir_ntfs, ntfstool, MFTECmd and a browser parser. When to use each.</description>
      <author>Florian Amette</author>
      <pubDate>Sun, 27 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>How Far Back Does the $LogFile Go? Limits and Pitfalls</title>
      <link>https://www.logfileparser.com/en/blog/logfile-limitations</link>
      <guid isPermaLink="true">https://www.logfileparser.com/en/blog/logfile-limitations</guid>
      <description>NTFS $LogFile retention in practice and its other blind spots: no clock, missing names, metadata only, rewritten by chkdsk or ntfs-3g, parsers that disagree.</description>
      <author>Florian Amette</author>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>A $LogFile Investigation Walkthrough (Fictional Case)</title>
      <link>https://www.logfileparser.com/en/blog/logfile-investigation-walkthrough</link>
      <guid isPermaLink="true">https://www.logfileparser.com/en/blog/logfile-investigation-walkthrough</guid>
      <description>A fictional intrusion on FIN-WKS-07 worked end to end from the NTFS $LogFile: rogue account, toolkit, backdated binary, rclone, a deleted note, and the report.</description>
      <author>Florian Amette</author>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>$LogFile Restart Area and LSNs Explained</title>
      <link>https://www.logfileparser.com/en/blog/logfile-restart-area-lsn</link>
      <guid isPermaLink="true">https://www.logfileparser.com/en/blog/logfile-restart-area-lsn</guid>
      <description>Inside the NTFS $LogFile restart pages: restart area fields, the NTFS client record, checkpoints, and how to turn a log sequence number into a file offset.</description>
      <author>Florian Amette</author>
      <pubDate>Sat, 19 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>$LogFile Format 1.1 vs 2.0: What Changed in Windows 8</title>
      <link>https://www.logfileparser.com/en/blog/logfile-version-1-1-vs-2-0</link>
      <guid isPermaLink="true">https://www.logfileparser.com/en/blog/logfile-version-1-1-vs-2-0</guid>
      <description>NTFS log format 1.1 and 2.0 side by side: tail pages vs 32 fast pages, where the circular area starts, why live captures show 2.0, and what parsers must do.</description>
      <author>Florian Amette</author>
      <pubDate>Thu, 17 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Recovering Deleted-File Evidence from the $LogFile</title>
      <link>https://www.logfileparser.com/en/blog/logfile-deleted-files-evidence</link>
      <guid isPermaLink="true">https://www.logfileparser.com/en/blog/logfile-deleted-files-evidence</guid>
      <description>What the NTFS $LogFile keeps after a deletion: name, folder, MFT entry, times, sizes, data runs, sometimes content. How to find it and what it cannot prove.</description>
      <author>Florian Amette</author>
      <pubDate>Tue, 15 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Detecting Timestomping with the NTFS $LogFile</title>
      <link>https://www.logfileparser.com/en/blog/detect-timestomping-logfile</link>
      <guid isPermaLink="true">https://www.logfileparser.com/en/blog/detect-timestomping-logfile</guid>
      <description>How $LogFile exposes timestomping: $STANDARD_INFORMATION before and after values, $SI vs $FN checks, four practical tells, false positives, and how to confirm.</description>
      <author>Florian Amette</author>
      <pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>NTFS $LogFile Redo/Undo Operations Explained</title>
      <link>https://www.logfileparser.com/en/blog/logfile-redo-undo-operations</link>
      <guid isPermaLink="true">https://www.logfileparser.com/en/blog/logfile-redo-undo-operations</guid>
      <description>The NTFS log record header byte by byte, the 38 redo/undo opcodes, which ones matter in forensics, and how create, delete, rename and timestamp changes look.</description>
      <author>Florian Amette</author>
      <pubDate>Thu, 10 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>How to Analyze an NTFS $LogFile, Step by Step</title>
      <link>https://www.logfileparser.com/en/blog/how-to-analyze-ntfs-logfile</link>
      <guid isPermaLink="true">https://www.logfileparser.com/en/blog/how-to-analyze-ntfs-logfile</guid>
      <description>A practical walkthrough: load $LogFile and $MFT in a browser parser, read the log header, triage flagged events, check raw redo/undo bytes and export results.</description>
      <author>Florian Amette</author>
      <pubDate>Tue, 08 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>How to Acquire the NTFS $LogFile (Live and Dead Box)</title>
      <link>https://www.logfileparser.com/en/blog/acquire-ntfs-logfile</link>
      <guid isPermaLink="true">https://www.logfileparser.com/en/blog/acquire-ntfs-logfile</guid>
      <description>Copy the locked NTFS $LogFile and its $MFT: KAPE, Velociraptor, FTK Imager, RawCopy, icat and ntfscat commands, plus checks that prove the copy is usable.</description>
      <author>Florian Amette</author>
      <pubDate>Sat, 05 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>$LogFile vs $UsnJrnl vs $MFT: Which NTFS Artifact When</title>
      <link>https://www.logfileparser.com/en/blog/logfile-vs-usnjrnl-vs-mft</link>
      <guid isPermaLink="true">https://www.logfileparser.com/en/blog/logfile-vs-usnjrnl-vs-mft</guid>
      <description>$LogFile, $UsnJrnl:$J and $MFT compared from the transaction log&apos;s side: what each records, how far back it goes, what only $LogFile proves, how to join them.</description>
      <author>Florian Amette</author>
      <pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>NTFS $LogFile Forensics: The Complete Guide</title>
      <link>https://www.logfileparser.com/en/blog/ntfs-logfile-forensics-guide</link>
      <guid isPermaLink="true">https://www.logfileparser.com/en/blog/ntfs-logfile-forensics-guide</guid>
      <description>What the NTFS $LogFile records, how its pages and redo/undo records work, what it proves in an investigation, how to collect it and where it stops.</description>
      <author>Florian Amette</author>
      <pubDate>Tue, 01 Sep 2026 00:00:00 GMT</pubDate>
    </item>
  </channel>
</rss>