A command utility for NTFS to search the MFT & monitoring the changes of USN Journal.
NTFS USN Journal parser 0.1.3
A command utility for NTFS to search the MFT & monitoring the changes of USN Journal.
Usage: UsnParser [command] [options]
Options:
--version Show version information.
-h|--help Show help information.
Commands:
monitor Monitor real-time USN journal changes
read Read history USN journal entries
search Search the Master File Table
Run 'UsnParser [command] -h|--help' for more information about a command.
# Search Master File Table of volume C, print out all paths who's file name is "Readme.md"
UsnParser search C: Readme.md
# Print out all the USN records of file "Readme.md" in volume C.
UsnParser read C: -f Readme.md
# Monitor realtime USN reacords of volume C.
UsnParser monitor C:
# Monitor realtime USN reacords of volume C, only print out txt files whose name starts with "abc".
UsnParser monitor C: -f abc*.txt