@port139 Blog

基本的にはデジタル・フォレンジックの技術について取り扱っていますが、記載内容には高確率で誤りが含まれる可能性があります。

Refs and USN Journal

Note:I translated Japanese into English using Google Translate.
Thank you, Google.

A little while ago I learned that ReFS supports the USN Journal.

How do I check the USN Journal on ReFS?

Format E: drive with ReFS.

f:id:hideakii:20181104141239p:plain

Start the administrator command prompt. Check the status of USN Journal with fsutil command.

For some reason, access is denied. Also I could confirm that USN journal is not valid.

f:id:hideakii:20181104141639p:plain

Enable USN Journal. However, the queryjournal option is access denied.

f:id:hideakii:20181104141919p:plain

f:id:hideakii:20181104142008p:plain

Create the Pictures folder and read the USN Journal. The readjournal command worked.(also tried the CSV option)

f:id:hideakii:20181104142326p:plain

f:id:hideakii:20181104142547p:plain

Copy example.jpg to the Pctures folder and browse.

f:id:hideakii:20181104142922p:plain

Since ReFS does not support ObjectID, ObjectID is not set.

f:id:hideakii:20181104143135p:plain

NTFS ADS is supported. Perhaps the USN Journal also exists as $J?

f:id:hideakii:20181104143335p:plain

So how do I get USN Journal data on ReFS in RAW format?

 

<add>

I exported the area of ReFS and tried Carving. Unfortunately, no USN record was found.

f:id:hideakii:20181104145714p:plain

f:id:hideakii:20181104145937p:plain

f:id:hideakii:20181104150106p:plain

 

Verification environment: Windows 10 1083

Reference URL:

https://en.wikipedia.org/wiki/ReFS

https://www.jpcert.or.jp/present/2018/JSAC2018_03_yamazaki.pdf

Bulk Extractor with Record Carving | Forensicist

 

f:id:hideakii:20181104140631j:plain