A command utility to read and monitor the NTFS/ReFS USN change Journal.
-
Updated
May 27, 2026 - C#
A command utility to read and monitor the NTFS/ReFS USN change Journal.
ARIN is Awesome ReFS Investigation tool
Although, reading Change Journal in windows by C++, this library should keep esay to use.
From-scratch NTFS reader (ntfs-core: MFT, attributes, indexes, data runs, LZNT1, $UsnJrnl:$J change journal over Read+Seek) plus a graded anomaly auditor (ntfs-forensic: timestomping, alternate data streams, deleted records, MFT/LogFile tamper checks) — panic-free, fuzzed, no unsafe
Add a description, image, and links to the change-journal topic page so that developers can more easily learn about it.
To associate your repository with the change-journal topic, visit your repo's landing page and select "manage topics."