Category Archives: Forensics

USN Analytics -Tool to Analyze USN Journal

USN Analytics is a tool that specializes in USN Journal ($UsnJrnl:$J) analysis. USN journal is an internal system list of the NTFS file system

OpenedFilesView – View Opened/Locked Files

OpenedFilesView displays the list of all opened files on your system. For each opened file, additional information is displayed: handle value, read/write

DMDE – DM Disk Editor and Data Recovery Software

DMDE is a powerful software for data searching, editing, and recovery on disks. It may recover directory structure and files in some complicated cases.

Glogg – Fast and Smart Log Explorer Tool

Glogg is a multi-platform GUI application that helps browse and search through long and complex log files. It is designed with programmers

sbag – TZWorks Windows ShellBag Parser

sbag is a Windows registry parser that targets the Shellbag subkeys to pull useful directory and file artifacts to help identify user activity.

JP- TZWorks Windows Journal Parser

JP is a command line tool that targets NTFS change log journals. The change journal is a component of NTFS that will, when enabled

Emailchemy – Email Migration Software

Emailchemy converts email from the closed, proprietary file formats of the most popular (and many of yesterday’s forgotten) email applications to standard