| |
# Summary NTFS maintains multiple independent audit trails—the Master File Table (MFT), USN Journal, and $LogFile—that attackers cannot fully suppress using standard methods, making file system activity recoverable even when timestamps are modified or tools are deleted. While attackers can modify the $STANDARD_INFORMATION timestamps, they cannot alter the $FILE_NAME timestamps or the sequential USN Journal records through standard APIs, leaving forensic evidence across different layers. Correlating all three artifacts using tools like dfir_ntfs and MFTECmd provides investigators with a robust, tamper-resistant timeline that is significantly harder to fully erase than individual logs or timestamps.
Read Full Article →
← More Tech news