USN-Journal-Parser Logo

USN-Journal-Parser

0
Free
Updated 11 March 2025
Visit Website

The NTFS USN Change journal is a volume-specific log which records metadata changes to files. It is a treasure trove of information during a forensic investigation. The change journal is a named alternate data stream, located at: $Extend$UsnJrnl:$J. usn.py is a script written in Python which parses the journal's contents, and features several different output formats. Default Output With no command-line options set, usn.py will produce USN journal records in the format below: dev@computer:$ python usn.py -f usnjournal -o /tmp/usn.txt dev@computer:$ cat /tmp/usn.txt 2016-01-26 18:56:20.046268 | test.vbs | ARCHIVE | DATA_OVERWRITE DATA_EXTEND Command-Line Options optional arguments: -h, --help show this help message and exit -b, --body Return USN records in comma-separated format -c, --csv Return USN records in comma-separated format -f FILE, --file FILE Parse the given USN journal file -q, --quick Parse a large journal file quickly -s SYSTEM, --system SYSTEM System name (use with -t) -t, --tln TLN output (use with -s) -v, --verbose Return all USN properties for each record (JSON) --csv Using the CSV f

FEATURES

SIMILAR TOOLS

Generate comprehensive reports about Windows systems with detailed system, security, networking, and USB information.

A tool for discovering, analyzing, and remedying sensitive data

ID-spoofing NFS client

A library to access FileVault Drive Encryption (FVDE) encrypted volumes on Mac OS X systems.

Fridump is an open source memory dumping tool using the Frida framework for dumping memory addresses from various platforms.

A library to access and parse Windows XML Event Log (EVTX) format, useful for digital forensics and incident response.

A suite of console tools for working with timestamps in Windows with 100-nanosecond precision.

A tool for triaging crash files with various output formats and debugging engine options.

A python module for orchestrating content acquisitions and analysis via Amazon SSM.

CyberSecTools logoCyberSecTools

Explore the largest curated directory of cybersecurity tools and resources to enhance your security practices. Find the right solution for your domain.

Operated by:

Mandos Cyber • KVK: 97994448

Netherlands • contact@mandos.io

VAT: NL005301434B12

Copyright © 2025 - All rights reserved