Be Kind, Rewind... The USN Journal

Поделиться
HTML-код
  • Опубликовано: 8 янв 2025

Комментарии • 14

  • @zomgninja
    @zomgninja 3 дня назад +2

    My favourite thing about forensics has always been that, given enough time, new techniques will be developed, uncovering new evidence. :)

  • @asharneyaz7
    @asharneyaz7 2 дня назад

    A great supplement to the "Parsing the MFT and USN Journal" lesson. Thank you so much, Richard!

  • @chocolatecoat3505
    @chocolatecoat3505 3 дня назад +1

    Great research, it’s amazing how it just takes some time and dedicated people to discover ways to uncover something new sitting right in front of us

  • @warlocksmurf
    @warlocksmurf 3 дня назад +2

    great video 13Cubed, one question though, so I can use this tool to act as a parser for both MFT+USN?

    • @13Cubed
      @13Cubed  3 дня назад +1

      You'll still want to use something like MFTECmd to parse the $MFT and $J. This tool expects the output from MFTECmd as input.

    • @warlocksmurf
      @warlocksmurf 3 дня назад

      @13Cubed ah right true that, thanks again!

  • @sidi7
    @sidi7 День назад

    hi I would like to ask, this python script is not same as -m flag in MFTECmd ? " -m $MFT file to use when -f points to a $J file (Use this to resolve parent path in $J CSV output)"

    • @13Cubed
      @13Cubed  День назад +1

      No, that would accomplish what I did in the first part of the demo -- the manual correlation. This is a completely different approach that I've not yet seen in any other tool.

  • @Manavetri
    @Manavetri 2 дня назад

    Very interesting and informative. But how can we be sure that the path is 100% the original and not some sort of "bug" or some problem with the tool? ... this same thing could be done manually ? knowing that the result get from the 2 same files we have

    • @13Cubed
      @13Cubed  2 дня назад

      Nothing is ever 100%. You could only say that "with high confidence" you believe this was the original path. You can also validate what the Python code is doing, and attempt to roll your own parsing methodology as well.

  • @ihacksi
    @ihacksi 2 дня назад

    We got USN Journal full file path trick before GTA6

    • @13Cubed
      @13Cubed  2 дня назад +1

      Hahaha indeed

  • @ScrimmyBetter
    @ScrimmyBetter 3 дня назад

    Youre my goat!