SecurityRonin / usnjrnl-forensic
PublicThe most comprehensive NTFS USN Journal parser: full path reconstruction (CyberCX Rewind), TriForce correlation (MFT + LogFile + UsnJrnl), ghost record recovery, anti-forensics detection, timestomping detection, USN carving, and more.
A forensics tool that rapidly analyzes Windows disk images to produce interactive HTML reports answering incident response questions and revealing file activity timelines.
How It Works
You hear about a tool that quickly analyzes file changes on Windows disks to spot incidents.
Download and set it up on your computer in moments—no complicated steps.
Choose the evidence file from your case, like a captured hard drive image.
Run one simple command pointing to your file, and in 30 seconds it finishes everything.
Click to view a beautiful, self-contained webpage right in your browser.
See instant answers to 12 key questions like 'Was malware dropped?' with matching evidence.
Hand the report to your incident commander—timeline, detections, and recovered deletions all ready.
Star Growth
Repurpose is a Pro feature
Generate ready-to-use prompts for X threads, LinkedIn posts, blog posts, YouTube scripts, and more -- with full repo context baked in.
Unlock RepurposeSimilar repos coming soon.