[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f0_yiPuyO3pvUSuxGZpBbqtZqgf8SxceQQBC7m5uG8L8":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":33,"aiModel":30,"aiConfidence":30,"updatedAt":49,"createdAt":49,"_status":48},244,"How does the USN Journal relate to NTFS file time attributes, and what additional insights does it provide?","While NTFS file time attributes (like last modified, creation time) can be modified by attackers, the USN Journal provides an independent chronology of file changes that is harder to alter without specialized tools. By cross-referencing the journal’s timestamps and reasons with the file’s metadata, investigators can spot discrepancies that reveal tampering. This complements the time attribute modification techniques discussed in [Penetration Techniques - Time Attributes of NTFS Files in Windows](\u002Fnews\u002Fpenetration-techniques-usn-journal-of-ntfs-files-in-windows).","\u003Cp>While NTFS file time attributes (like last modified, creation time) can be modified by attackers, the USN Journal provides an independent chronology of file changes that is harder to alter without specialized tools. By cross-referencing the journal’s timestamps and reasons with the file’s metadata, investigators can spot discrepancies that reveal tampering. This complements the time attribute modification techniques discussed in [Penetration Techniques - Time Attributes of NTFS Files in Windows](\u002Fnews\u002Fpenetration-techniques-usn-journal-of-ntfs-files-in-windows).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fpenetration-techniques-usn-journal-of-ntfs-files-in-windows\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-does-the-usn-journal-relate-to-ntfs-file-time-attributes-and-what-additional-1777484541789","NTFS time attributes, USN Journal, file timeline, timestamp tampering, forensic cross-check",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":27,"cover":30,"author":31,"views":19,"readingTime":32,"status":33,"publishedAt":34,"seo":35,"tags":39,"qaPairs":40,"meta":45,"updatedAt":46,"createdAt":47,"_status":48},63,"Penetration Techniques - USN Journal of NTFS Files in Windows","penetration-techniques-usn-journal-of-ntfs-files-in-windows","Explore USN Journal in NTFS files for penetration techniques, reading methods, exploitation approaches, and forensic recommendations in Windows systems.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In the previous article 'Penetration Techniques - Time Attributes of NTFS Files in Windows', methods and details for modifying NTFS file time attributes, as well as forensic recommendations, were introduced.\u003C\u002Fp>\u003Cp>This article will continue to explore another location in NTFS files that records file modification times—the USN Journal, similarly analyzing exploitation approaches and providing forensic recommendations.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Basic Concepts\u003C\u002Fli>\u003Cli>Methods for Reading the USN Journal\u003C\u002Fli>\u003Cli>Exploitation Approaches\u003C\u002Fli>\u003Cli>Forensic Recommendations\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Basic Concepts of USN Journal\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Official Documentation:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fprevious-versions\u002Fwindows\u002Fit-pro\u002Fwindows-2000-server\u002Fbb742450(v=technet.10)\u003C\u002Fp>\u003Cp>USN Journal (Update Sequence Number Journal), also known as Change Journal, is used to record file modification information on NTFS volumes, improving file search efficiency\u003C\u002Fp>\u003Cp>Each NTFS volume corresponds to a USN Journal, stored in the NTFS metafile $Extend\\$UsnJrnl, meaning different NTFS volumes have distinct USN Journals\u003C\u002Fp>\u003Cp>USN Journal records file and directory operations including creation, deletion, modification, renaming, and encryption\u002Fdecryption. Each record follows this format:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>typedef struct {\u003Cbr>  DWORD         RecordLength;\u003Cbr>  WORD          MajorVersion;\u003Cbr>  WORD          MinorVersion;\u003Cbr>  DWORDLONG     FileReferenceNumber;\u003Cbr>  DWORDLONG     ParentFileReferenceNumber;\u003Cbr>  USN           Usn;\u003Cbr>  LARGE_INTEGER TimeStamp;\u003Cbr>  DWORD         Reason;\u003Cbr>  DWORD         SourceInfo;\u003Cbr>  DWORD         SecurityId;\u003Cbr>  DWORD         FileAttributes;\u003Cbr>  WORD          FileNameLength;\u003Cbr>  WORD          FileNameOffset;\u003Cbr>  WCHAR         FileName[1];\u003Cbr>} USN_RECORD_V2, *PUSN_RECORD_V2;\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Official documentation:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fwindows\u002Fdesktop\u002Fapi\u002Fwinioctl\u002Fns-winioctl-usn_record_v2\u003C\u002Fp>\u003Cp>The total size of the USN Journal file is stored in the NTFS metafile $Extend\\$UsnJrnl\\$Max. If the record length of the USN Journal exceeds the total size, it will overwrite from the earliest records.\u003C\u002Fp>\u003Ch2>0x03 Method for reading USN Journal\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Using the fsutil usn command\u003C\u002Fh3>\u003Cp>Official documentation:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fprevious-versions\u002Fwindows\u002Fit-pro\u002Fwindows-server-2008-R2-and-2008\u002Fcc788042(v%3dws.10)\u003C\u002Fp>\u003Ch4>(1) View USN Journal information for drive C:\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>fsutil usn queryjournal c:\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Including the following information:\u003C\u002Fp>\u003Cul>\u003Cli>Usn Journal ID\u003C\u002Fli>\u003Cli>First Usn\u003C\u002Fli>\u003Cli>Next Usn\u003C\u002Fli>\u003Cli>Lowest Valid Usn\u003C\u002Fli>\u003Cli>Max Usn\u003C\u002Fli>\u003Cli>Maximum Size\u003C\u002Fli>\u003Cli>Allocation Delta\u003C\u002Fli>\u003C\u002Ful>\u003Ch4>(2) View all USN Journal on drive C\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>fsutil usn enumdata 1 0 1 c:\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Including the following information:\u003C\u002Fp>\u003Cul>\u003Cli>File Ref#\u003C\u002Fli>\u003Cli>ParentFile Ref#\u003C\u002Fli>\u003Cli>Usn\u003C\u002Fli>\u003Cli>SecurityId\u003C\u002Fli>\u003Cli>Reason\u003C\u002Fli>\u003Cli>Name\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Output results are not detailed enough\u003C\u002Fp>\u003Ch3>2. Using open-source tools\u003C\u002Fh3>\u003Ch4>(1) Export USN Journal\u003C\u002Fh4>\u003Cp>Download link:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fjschicht\u002FExtractUsnJrnl\u003C\u002Fp>\u003Cp>Parameters are as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ExtractUsnJrnl \u002FDevicePath:c: \u002FOutputPath:c:\\test \u002FOutputName:UsnJrnl_vol1.bin\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(2) Convert USN Journal to CSV format output\u003C\u002Fh4>\u003Cp>Download link:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fjschicht\u002FUsnJrnl2Csv\u003C\u002Fp>\u003Cp>Parameters are as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>UsnJrnl2Csv \u002FUsnJrnlFile:c:\\test\\UsnJrnl_vol1.bin \u002FOutputPath:c:\\test\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Includes the following information:\u003C\u002Fp>\u003Cul>\u003Cli>Offset\u003C\u002Fli>\u003Cli>FileName\u003C\u002Fli>\u003Cli>USN\u003C\u002Fli>\u003Cli>Timestamp\u003C\u002Fli>\u003Cli>Reason\u003C\u002Fli>\u003Cli>MFTReference\u003C\u002Fli>\u003Cli>MFTReferenceSeqNo\u003C\u002Fli>\u003Cli>MFTParentReference\u003C\u002Fli>\u003Cli>MFTParentReferenceSeqNo\u003C\u002Fli>\u003Cli>FileAttributes\u003C\u002Fli>\u003Cli>MajorVersion\u003C\u002Fli>\u003Cli>MinorVersion\u003C\u002Fli>\u003Cli>SourceInfo\u003C\u002Fli>\u003Cli>SecurityId\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Output results are complete\u003C\u002Fp>\u003Ch3>3. C++ Implementation\u003C\u002Fh3>\u003Cp>I've written a simple sample code here, download link:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code enumerates the USN Journal of drive C and outputs only filenames\u003C\u002Fp>\u003Ch2>0x04 Exploitation Approach\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Clear All USN Journals\u003C\u002Fh3>\u003Ch4>(1) Using fsutil\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>fsutil usn deletejournal \u002Fd c:\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>I did not succeed in deleting it in the test environment\u003C\u002Fp>\u003Ch4>(2) API\u003C\u002Fh4>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fwindows\u002Fdesktop\u002Fapi\u002Fwinioctl\u002Fns-winioctl-delete_usn_journal_data\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>I did not succeed in deleting it in the test environment\u003C\u002Fp>\u003Ch3>2. Clear single USN Journal\u003C\u002Fh3>\u003Cp>I have not yet found an available API interface\u003C\u002Fp>\u003Cp>The only method is to directly modify NTFS files, but since nt6.x, Windows prohibits loading unsigned driver files\u003C\u002Fp>\u003Cp>Here you can try using the paid version of WinHex to operate on NTFS files, modifying the content in $Extend\\$UsnJrnl\u003C\u002Fp>\u003Cp>You can also try to bypass driver protection\u003C\u002Fp>\u003Cp>For reference on the content of $UsnJrnl:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fforensicinsight.org\u002Fwp-content\u002Fuploads\u002F2013\u002F07\u002FF-INSIGHT-Advanced-UsnJrnl-Forensics-English.pdf\u003C\u002Fp>\u003Cp>Read the USN Journal according to the format, delete the specified USN Journal, and then write it to the disk\u003C\u002Fp>\u003Ch3>3. Brute force overwriting\u003C\u002Fh3>\u003Cp>First, check the total length of the disk's USN Journal file\u003C\u002Fp>\u003Cp>Then generate USN Journal records through operations such as creation, deletion, modification, and renaming. When the total length is exceeded, the initial records will be overwritten until all USN Journals are covered\u003C\u002Fp>\u003Ch2>0x05 Forensic Recommendations\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch4>1. Read the USN Journal, list all records, and check for any suspicious records\u003C\u002Fh4>\u003Cp>This method is not completely reliable; as long as attackers can bypass driver protection, they can modify the USN Journal\u003C\u002Fp>\u003Ch4>2. Try other methods\u003C\u002Fh4>\u003Cp>For example, reading $MFT records from memory\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fjschicht\u002FHexDump\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fjschicht\u002FMftCarver\u003C\u002Fp>\u003Cp>Joakim Schicht's GitHub has many forensic tools worth referencing:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fjschicht\u002F\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the utilization ideas of NTFS file's USN Journal and provides forensic recommendations.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr",null,"Onedaysec",3,"published","2026-02-02T08:07:20.755Z",{"title":36,"description":14,"keywords":37,"ogImage":30,"canonicalUrl":30,"noIndex":38},"USN Journal NTFS File Penetration Techniques & Forensics Guide","USN Journal, NTFS files, penetration techniques, Windows forensics, file modification tracking, USN Journal exploitation, NTFS volume, Change Journal, forensic recommendations",false,[],{"docs":41,"hasNextPage":38},[4,42,43,44],243,242,241,{"title":30,"description":30,"image":30},"2026-07-24T02:07:27.472Z","2026-07-23T16:01:14.562Z","draft","2026-07-23T16:04:47.528Z"]