disk_parse_usn_journal
Retrieve file system change history by parsing the USN Journal, uncovering file creation, deletion, modification, and rename operations with precise timestamps.
Instructions
Parse $UsnJrnl:$J (USN Journal) for file system change history. Records file creation, deletion, modification, and rename operations. Answers: What files were created/deleted/renamed? When did file changes occur?
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| usn_path | Yes | Path to $J file (typically $Extend/$J) | |
| filename_filter | No | Filter by filename (case-insensitive substring) | |
| reason_filter | No | Filter by reason types (e.g., FILE_CREATE, FILE_DELETE, RENAME_NEW_NAME) | |
| time_range_start | No | ISO format datetime - filter events after this time | |
| time_range_end | No | ISO format datetime - filter events before this time | |
| interesting_only | No | Only return forensically interesting changes (create, delete, rename, modify) | |
| files_only | No | Only return file events (exclude directories) | |
| output_mode | No | Output mode: records (individual changes), summary (statistics), deleted_files (only deletions) | records |
| extension_filter | No | Filter by file extension (for deleted_files mode) | |
| limit | No | Maximum number of records to return |