• Home
  • Products
  • Training
  • Support
  • About Us
  • Forum
  • Sign In

$UsnJrnl Viewer

Discover
  • Find files faster
  • Search within files
  • Search for E-mails
  • Recover deleted files
  • Uncover User Activity
  • Collect system information
  • Password recovery
  • Hidden Disk Areas - HPA/DCO
  • Volume Shadow Copy
  • Web Browser
Identify
  • Verify and match files
  • Find misnamed files
  • Compare drive signatures
  • Timeline viewer
  • File viewer
  • Memory viewer
  • Binary String Extraction
  • Email viewer
  • Registry viewer
  • File system browser
  • Raw disk viewer
  • Thumbnail cache viewer
  • SQLite database browser
  • ESE database browser
  • Prefetch viewer
  • $UsnJrnl viewer
  • Plist viewer
  • Event Log Viewer
  • Web Server Log Viewer
Manage
  • Case management
  • Generate reports
  • Storage device management
  • Drive Imaging
  • Cloud Drive Imaging
  • Cloud Account Imaging
  • Rebuild RAID arrays
  • Portability
  • Secure case logging
  • Support

UsnJrnl ViewerOSForensics™ includes an $UsnJrnl viewer that parses and displays the log records stored in the NTFS $UsnJrnl volume change journal. This information is useful for identifying suspect files (eg. malware) that no longer exist in the file system or $MFT. The USN journal is updated whenever changes to files and directories are made to a volume including:

  • File Metadata changes
  • File Creations
  • File Deletions
  • File Overwrites

The $UsnJrnl viewer allows the user to search for records that match a specified text phrase.

UsnJrnl Viewer

Home
Discover Identify Manage
Contact Us Legal Disclaimer Privacy Policy
Products
OSForensics OSForensics Bootable (USB Flash Drive) Rainbow Tables - 3TB hard disk
Training
Online Training Course Certification Exam - Online Triage Exam - Online Face-to-Face Classes 2024 Events Calendar
Support
Video Demonstrations FAQs and Tutorials OSForensics Forums Australian Head Office North American Branch

Copyright © 2025 PassMark™ Software