<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>NTFS $LogFile Parser — Blog</title>
    <link>https://www.logfileparser.com/fr/blog</link>
    <description>Latest from Blog</description>
    <language>fr</language>
    <lastBuildDate>Sun, 27 Sep 2026 20:44:11 GMT</lastBuildDate>
    <atom:link href="https://www.logfileparser.com/fr/blog/feed.xml" rel="self" type="application/rss+xml"/>
    <item>
      <title>Comparatif des parseurs de $LogFile NTFS</title>
      <link>https://www.logfileparser.com/fr/blog/logfile-parser-comparison</link>
      <guid isPermaLink="true">https://www.logfileparser.com/fr/blog/logfile-parser-comparison</guid>
      <description>Comparatif factuel des outils $LogFile : LogFileParser, NTFS Log Tracker, TZWorks mala, dfir_ntfs, ntfstool, MFTECmd et un parseur web. Quoi utiliser, et quand.</description>
      <author>Florian Amette</author>
      <pubDate>Sun, 27 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Jusqu&apos;où remonte le $LogFile ? Limites et pièges</title>
      <link>https://www.logfileparser.com/fr/blog/logfile-limitations</link>
      <guid isPermaLink="true">https://www.logfileparser.com/fr/blog/logfile-limitations</guid>
      <description>Rétention réelle du $LogFile NTFS et ses angles morts : pas d&apos;horloge, noms manquants, métadonnées seules, réécrit par chkdsk ou ntfs-3g, parseurs divergents.</description>
      <author>Florian Amette</author>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Étude de cas $LogFile : une enquête fictive pas à pas</title>
      <link>https://www.logfileparser.com/fr/blog/logfile-investigation-walkthrough</link>
      <guid isPermaLink="true">https://www.logfileparser.com/fr/blog/logfile-investigation-walkthrough</guid>
      <description>Une intrusion fictive sur FIN-WKS-07 traitée avec le $LogFile NTFS : compte illégitime, binaire antidaté, rclone, note supprimée, puis rédaction du rapport.</description>
      <author>Florian Amette</author>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Zone de redémarrage et LSN du $LogFile expliqués</title>
      <link>https://www.logfileparser.com/fr/blog/logfile-restart-area-lsn</link>
      <guid isPermaLink="true">https://www.logfileparser.com/fr/blog/logfile-restart-area-lsn</guid>
      <description>Les pages de redémarrage du $LogFile NTFS : champs de la zone de redémarrage, client NTFS, points de contrôle, et comment convertir un LSN en offset.</description>
      <author>Florian Amette</author>
      <pubDate>Sat, 19 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Format du $LogFile 1.1 et 2.0 : ce qui change avec Windows 8</title>
      <link>https://www.logfileparser.com/fr/blog/logfile-version-1-1-vs-2-0</link>
      <guid isPermaLink="true">https://www.logfileparser.com/fr/blog/logfile-version-1-1-vs-2-0</guid>
      <description>Formats de journal NTFS 1.1 et 2.0 : pages de queue ou 32 pages rapides, début de la zone circulaire, captures à chaud en 2.0 et impact sur les parseurs.</description>
      <author>Florian Amette</author>
      <pubDate>Thu, 17 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>$LogFile : retrouver les traces de fichiers supprimés</title>
      <link>https://www.logfileparser.com/fr/blog/logfile-deleted-files-evidence</link>
      <guid isPermaLink="true">https://www.logfileparser.com/fr/blog/logfile-deleted-files-evidence</guid>
      <description>Ce que garde le $LogFile NTFS après une suppression : nom, dossier, entrée MFT, dates, tailles, runs, parfois le contenu. Où le trouver, ce qu&apos;il ne prouve pas.</description>
      <author>Florian Amette</author>
      <pubDate>Tue, 15 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Détecter le timestomping avec le $LogFile NTFS</title>
      <link>https://www.logfileparser.com/fr/blog/detect-timestomping-logfile</link>
      <guid isPermaLink="true">https://www.logfileparser.com/fr/blog/detect-timestomping-logfile</guid>
      <description>Comment le $LogFile trahit le timestomping : valeurs $SI avant et après, contrôle $SI/$FN, quatre indices concrets, faux positifs et méthode pour confirmer.</description>
      <author>Florian Amette</author>
      <pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Les opérations redo/undo du $LogFile NTFS expliquées</title>
      <link>https://www.logfileparser.com/fr/blog/logfile-redo-undo-operations</link>
      <guid isPermaLink="true">https://www.logfileparser.com/fr/blog/logfile-redo-undo-operations</guid>
      <description>L&apos;en-tête d&apos;enregistrement du journal NTFS octet par octet, les 38 opcodes redo/undo, ceux qui comptent en forensique, et à quoi ressemble chaque action.</description>
      <author>Florian Amette</author>
      <pubDate>Thu, 10 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Analyser un $LogFile NTFS pas à pas</title>
      <link>https://www.logfileparser.com/fr/blog/how-to-analyze-ntfs-logfile</link>
      <guid isPermaLink="true">https://www.logfileparser.com/fr/blog/how-to-analyze-ntfs-logfile</guid>
      <description>Méthode pratique : charger $LogFile et $MFT dans un parseur web, lire l&apos;en-tête du journal, trier les événements signalés, vérifier le redo/undo, exporter.</description>
      <author>Florian Amette</author>
      <pubDate>Tue, 08 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Acquérir le $LogFile NTFS (à chaud et à froid)</title>
      <link>https://www.logfileparser.com/fr/blog/acquire-ntfs-logfile</link>
      <guid isPermaLink="true">https://www.logfileparser.com/fr/blog/acquire-ntfs-logfile</guid>
      <description>Copier le $LogFile NTFS verrouillé et son $MFT : commandes KAPE, Velociraptor, FTK Imager, RawCopy, icat et ntfscat, et les contrôles qui valident la copie.</description>
      <author>Florian Amette</author>
      <pubDate>Sat, 05 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>$LogFile, $UsnJrnl ou $MFT : quel artefact NTFS, et quand</title>
      <link>https://www.logfileparser.com/fr/blog/logfile-vs-usnjrnl-vs-mft</link>
      <guid isPermaLink="true">https://www.logfileparser.com/fr/blog/logfile-vs-usnjrnl-vs-mft</guid>
      <description>$LogFile, $UsnJrnl:$J et $MFT comparés du point de vue du journal de transactions : contenu, profondeur, ce que seul le $LogFile prouve, comment les relier.</description>
      <author>Florian Amette</author>
      <pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Analyse forensique du $LogFile NTFS : le guide complet</title>
      <link>https://www.logfileparser.com/fr/blog/ntfs-logfile-forensics-guide</link>
      <guid isPermaLink="true">https://www.logfileparser.com/fr/blog/ntfs-logfile-forensics-guide</guid>
      <description>Ce que journalise le $LogFile NTFS, comment fonctionnent ses pages et ses opérations redo/undo, ce qu&apos;il prouve en enquête, comment l&apos;acquérir et ses limites.</description>
      <author>Florian Amette</author>
      <pubDate>Tue, 01 Sep 2026 00:00:00 GMT</pubDate>
    </item>
  </channel>
</rss>