Going beneath NTFS: USN Journal, dfir_NTFS, and artefact-driven investigations

This article explains how NTFS file system structures, specifically the Master File Table, USN Journal, and $LogFile, provide a layered audit trail for forensic investigators. It emphasizes that correlating these redundant data sources makes it difficult for attackers to hide their tracks by modifying timestamps.
Why it matters
Understanding these low-level file system artifacts is critical for cybersecurity professionals conducting incident response and digital forensics.
Jul 6, 2026 by Andrea Fortuna A skilled attacker who has spent any time studying forensics will know to modify file timestamps. Some will go further and delete their tools, clear event logs, and rename artefacts before exfiltrating or detonating. What most do not account for, because most training does not cover it carefully, is that NTFS keeps a layered audit trail spread across at least three separate structures, and cleaning one of them rarely touches the others.
The content is purely technical and educational, focusing on forensic methodology.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in