<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>NTFS $LogFile Parser — Blog</title>
    <link>https://www.logfileparser.com/es/blog</link>
    <description>Latest from Blog</description>
    <language>es</language>
    <lastBuildDate>Sun, 27 Sep 2026 20:44:11 GMT</lastBuildDate>
    <atom:link href="https://www.logfileparser.com/es/blog/feed.xml" rel="self" type="application/rss+xml"/>
    <item>
      <title>Analizadores de $LogFile: LogFileParser, NTFS Log Tracker</title>
      <link>https://www.logfileparser.com/es/blog/logfile-parser-comparison</link>
      <guid isPermaLink="true">https://www.logfileparser.com/es/blog/logfile-parser-comparison</guid>
      <description>Comparativa de herramientas para el $LogFile de NTFS: LogFileParser, NTFS Log Tracker, mala, dfir_ntfs, ntfstool, MFTECmd y un parser web. Cuándo usar cada una.</description>
      <author>Florian Amette</author>
      <pubDate>Sun, 27 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>¿Hasta dónde llega el $LogFile? Límites y trampas</title>
      <link>https://www.logfileparser.com/es/blog/logfile-limitations</link>
      <guid isPermaLink="true">https://www.logfileparser.com/es/blog/logfile-limitations</guid>
      <description>Retención real del $LogFile de NTFS y sus otros puntos ciegos: sin reloj, sin nombres, solo metadatos, reescrito por chkdsk o ntfs-3g, parsers discrepantes.</description>
      <author>Florian Amette</author>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Investigación con el $LogFile paso a paso (caso ficticio)</title>
      <link>https://www.logfileparser.com/es/blog/logfile-investigation-walkthrough</link>
      <guid isPermaLink="true">https://www.logfileparser.com/es/blog/logfile-investigation-walkthrough</guid>
      <description>Una intrusión ficticia en FIN-WKS-07 resuelta con el $LogFile de NTFS: cuenta falsa, herramientas, binario antedatado, rclone, una nota borrada y el informe.</description>
      <author>Florian Amette</author>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>$LogFile: el área de reinicio y los LSN, explicados</title>
      <link>https://www.logfileparser.com/es/blog/logfile-restart-area-lsn</link>
      <guid isPermaLink="true">https://www.logfileparser.com/es/blog/logfile-restart-area-lsn</guid>
      <description>En las páginas de reinicio del $LogFile de NTFS: campos del área de reinicio, registro de cliente NTFS, checkpoints y cómo pasar un LSN a un desplazamiento.</description>
      <author>Florian Amette</author>
      <pubDate>Sat, 19 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>$LogFile 1.1 frente a 2.0: qué cambió en Windows 8</title>
      <link>https://www.logfileparser.com/es/blog/logfile-version-1-1-vs-2-0</link>
      <guid isPermaLink="true">https://www.logfileparser.com/es/blog/logfile-version-1-1-vs-2-0</guid>
      <description>Formatos 1.1 y 2.0 del diario NTFS: páginas de cola frente a 32 páginas rápidas, inicio del área circular, capturas en vivo y qué debe hacer un parser.</description>
      <author>Florian Amette</author>
      <pubDate>Thu, 17 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>$LogFile: recuperar evidencias de archivos borrados</title>
      <link>https://www.logfileparser.com/es/blog/logfile-deleted-files-evidence</link>
      <guid isPermaLink="true">https://www.logfileparser.com/es/blog/logfile-deleted-files-evidence</guid>
      <description>Qué conserva el $LogFile de NTFS tras un borrado: nombre, carpeta, entrada MFT, fechas, tamaños, data runs y a veces contenido. Cómo hallarlo y sus límites.</description>
      <author>Florian Amette</author>
      <pubDate>Tue, 15 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Detectar timestomping con el $LogFile de NTFS</title>
      <link>https://www.logfileparser.com/es/blog/detect-timestomping-logfile</link>
      <guid isPermaLink="true">https://www.logfileparser.com/es/blog/detect-timestomping-logfile</guid>
      <description>Cómo delata el $LogFile el timestomping: valores de $STANDARD_INFORMATION antes y después, $SI frente a $FN, cuatro indicios, falsos positivos y cómo confirmar.</description>
      <author>Florian Amette</author>
      <pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Las operaciones redo/undo del $LogFile de NTFS, explicadas</title>
      <link>https://www.logfileparser.com/es/blog/logfile-redo-undo-operations</link>
      <guid isPermaLink="true">https://www.logfileparser.com/es/blog/logfile-redo-undo-operations</guid>
      <description>La cabecera de un registro del diario NTFS byte a byte, los 38 opcodes redo/undo, cuáles importan en forense y cómo se ven creación, borrado y renombrado.</description>
      <author>Florian Amette</author>
      <pubDate>Thu, 10 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Cómo analizar un $LogFile de NTFS paso a paso</title>
      <link>https://www.logfileparser.com/es/blog/how-to-analyze-ntfs-logfile</link>
      <guid isPermaLink="true">https://www.logfileparser.com/es/blog/how-to-analyze-ntfs-logfile</guid>
      <description>Un recorrido práctico: cargar $LogFile y $MFT en un analizador web, leer la cabecera, priorizar eventos marcados, revisar los bytes redo/undo y exportar.</description>
      <author>Florian Amette</author>
      <pubDate>Tue, 08 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Cómo adquirir el $LogFile de NTFS (en vivo y en frío)</title>
      <link>https://www.logfileparser.com/es/blog/acquire-ntfs-logfile</link>
      <guid isPermaLink="true">https://www.logfileparser.com/es/blog/acquire-ntfs-logfile</guid>
      <description>Copiar el $LogFile bloqueado de NTFS y su $MFT: comandos de KAPE, Velociraptor, FTK Imager, RawCopy, icat y ntfscat, y comprobaciones de que la copia sirve.</description>
      <author>Florian Amette</author>
      <pubDate>Sat, 05 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>$LogFile, $UsnJrnl o $MFT: qué artefacto NTFS y cuándo</title>
      <link>https://www.logfileparser.com/es/blog/logfile-vs-usnjrnl-vs-mft</link>
      <guid isPermaLink="true">https://www.logfileparser.com/es/blog/logfile-vs-usnjrnl-vs-mft</guid>
      <description>$LogFile, $UsnJrnl:$J y $MFT comparados desde el diario de transacciones: qué registra cada uno, cuánto abarca, qué solo prueba el $LogFile y cómo cruzarlos.</description>
      <author>Florian Amette</author>
      <pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Análisis forense del $LogFile de NTFS: la guía completa</title>
      <link>https://www.logfileparser.com/es/blog/ntfs-logfile-forensics-guide</link>
      <guid isPermaLink="true">https://www.logfileparser.com/es/blog/ntfs-logfile-forensics-guide</guid>
      <description>Qué registra el $LogFile de NTFS, cómo funcionan sus páginas y registros redo/undo, qué demuestra en una investigación, cómo adquirirlo y dónde se queda corto.</description>
      <author>Florian Amette</author>
      <pubDate>Tue, 01 Sep 2026 00:00:00 GMT</pubDate>
    </item>
  </channel>
</rss>