Sie sind auf Seite 1von 14

FORENSIC INSIGHT;

DIGITAL FORENSICS COMMUNITY IN KOREA

User Manual of NTFS Log Tracker

blueangel

blueangel1275@gmail.com

http://forensic-note.blogspot.kr/

Junghoon Oh
1. User Interface

2. Basis Instructions

3. Search & Export Instructions

4. Opening DB

5. Conclusion

forensicinsight.org Page 2
User Interface

forensicinsight.org Page 3
User Interface

User Interface of NTFS Log Tracker v1.4

Source File for Parsing

$MFT for
Full Path Construction
Opening DB file
created by this tool

Keyword Search
Exporting CSV format

Parsed Data Output

forensicinsight.org Page 4
Basis Instructions

forensicinsight.org Page 5
Basis Instructions

STEP 1. Input of source file


1) Enter the path of source file($LogFile, $UsnJrnl:$J, Unallocated Dump File)
The tool can start its operation when more than one path is entered.

2) If the tool has path of $MFT file additionally, it can print full path information of event.

3) Click Parsing button~!!

forensicinsight.org Page 6
Basis Instructions

STEP 2. Input of SQLite DB name & path


1) Enter the name and path of SQLite DB which saves the parsing result.

The information of time(YYYY-MM-DD HH-MM-SS) is added on DB name.

2) Click OK Button~!!

forensicinsight.org Page 7
Basis Instructions

STEP 3. Parsing Result


After parsing, the parsing result is printed out in each tabs.

If the parsing result is more than 500,000 record, it is printed by page unit.
<, > button : moving to previous or after page

Index combo box : moving to page which corresponds specific period

forensicinsight.org Page 8
Search & Export Instructions

forensicinsight.org Page 9
Search & Export Instructions

Keyword Search
1) Click Search button~!!

2) Enter keyword you want.


The result of search is printed out in Search Result tab.

If multi-keyword are entered, the keywords are used by AND operation.

forensicinsight.org Page 10
Search & Export Instructions

CSV Export
1) Click CSV Export button~!!

2) Select the path of CSV file.

forensicinsight.org Page 11
Opening DB

forensicinsight.org Page 12
Opening DB

Opening SQLite DB that you made previously


1) After Selecting the path of SQLite DB, click Open button~!!

2) Confirm the paring result.

forensicinsight.org Page 13
If you have any bug, question while using my tool, email me~!!

blueangel1275@gmail.com

forensicinsight.org Page 14

Das könnte Ihnen auch gefallen