SKIP TO CONTENT
FILESYSTEM METADATA AND TIMESTAMPS27 / 36

$UsnJrnl (USN Change Journal)

Also called USN journal, change journal, UsnJrnl $J, NTFS change journal.

PLATFORM
Windows
CATEGORY
Filesystem Metadata and Timestamps
INDEX
27 of 36
PROVES
5 findings
CANNOT PROVE
5 limits
QUESTIONS
3 answered
WHAT IT IS

A per-volume journal recording every change to every file — creation, deletion, rename, data overwrite — with a timestamp, a filename and a reason code for each entry.

Where it lives

\$Extend\$UsnJrnl, in its $J data stream, on each NTFS volume

Name the location in the preservation request rather than describing the artifact in general terms. A request that asks for the record by its path is one the responding party can act on and one a court can enforce; a request for “all forensic evidence of $usnjrnl (usn change journal)” is neither.

What it records

Each change to a file or directory produces a record naming the file, its parent directory reference, a timestamp and a set of reason flags describing what changed: data written, file created, file deleted, old and new names on a rename, and the close of a handle. The journal is a sparse stream with a maximum size; as it grows past that size the oldest records are released, so the window is a function of volume activity.

What it proves — and what it cannot

These two panels carry equal weight, deliberately. The right-hand column is not a disclaimer: it is the specific, mechanical reason an inference fails, and it is the column opposing counsel will read back to a witness on cross-examination.

What it proves

FINDINGS THIS ARTIFACT WILL SUPPORT ON ITS OWN TERMS.

  • That a named file was created, renamed, modified or deleted on this volume, at a recorded time
  • Renames in both directions, since old and new names are recorded — which is how staging and disguise are identified
  • Bulk activity patterns: hundreds of creations in a directory within minutes, or a mass deletion at a single moment
  • That files existed which appear nowhere else, because the record survives the file
  • Activity on a removable volume, where the volume itself was produced and carries its own journal

What it cannot prove

INFERENCES IT WILL NOT CARRY, HOWEVER STRONGLY IT POINTS.

  • Who made a change. Change journal records carry no user or process identity of any kind
  • That a file was copied. A copy creates a record on the destination volume, so the journal on the source machine shows a read that leaves no distinguishing mark — the destination volume is where the evidence would be, and it is usually the drive nobody has
  • File content, or how much data was written. Reason flags describe the type of change, not its magnitude or its substance
  • Anything before the journal rolled. Coverage is a function of volume activity and on a busy volume can be days or less
  • Intent from a reason flag. A deletion flag records a deletion, and the artifact holds nothing about why

How the finding is attacked

An opinion built on this artifact meets these arguments. Each of them is answerable, and each of them is answered before the report is served rather than at a deposition.

  • Establishing the earliest surviving record and showing the disputed period is not covered
  • Pointing out the absence of user attribution where the opinion names a person
  • Arguing that a burst of creations is consistent with an ordinary application operation such as an update, an extraction, or a backup
  • Noting that the journal can be deleted and recreated by an administrator, so its state is not tamper-evident

What survives, and for how long

Records persist until the journal exceeds its maximum size and the oldest are released, which on an active volume commonly means days to weeks. Deleting the journal is a single administrative command; recreating it starts a fresh sequence, which is itself detectable from the sequence numbers.

More matters are decided by what an artifact never kept than by what it says, which makes preservation timing the most consequential decision in the matter — and it is usually made months before anyone examines anything. The evidence preservation deadline calculator works from the date you first anticipated litigation.

Questions counsel ask

What does the USN change journal record?

Every change to every file and directory on the volume: creation, data overwrite, rename with both old and new names, deletion, and the closing of a handle, each with a timestamp and a reason flag. It is the most complete file-level activity record Windows keeps. It carries no user attribution and no file content, and it rolls as the volume stays busy.

Does the change journal prove files were copied to a USB drive?

Not from the source machine. A copy creates new files on the destination volume, so the records that would evidence it sit in the removable drive's own journal — the drive that is usually not produced. On the source, reading a file for a copy leaves nothing that distinguishes it from opening the file. The copy inference has to be built from other artifacts.

How long does the USN journal keep records?

Until the journal exceeds its maximum size, at which point the oldest records are released — so the window is governed by volume activity rather than by time, and on an active volume it commonly amounts to days or a few weeks. A matter concerning conduct from six months ago will usually find nothing in it unless the volume was quiet or a shadow copy holds an older version.

Terms used on this page

Every term below is defined in the forensic glossary — what it is, why a case turns on it, and what happens when it is mishandled.

No artifact carries a matter on its own. These are the records that corroborate, contradict, or supply the timeline this one cannot.

A FINDING ON THIS ARTIFACT

Whether the $usnjrnl (usn change journal)evidence in your matter supports the opinion built on it is a question with a testable answer. Law & Forensics retains court-tested digital forensic expert witnesses and forensic neutrals.

A conflicts check and scoping call follow, normally within one business day. Please do not send privileged or case-sensitive material until conflicts have cleared.

WEEKLY BRIEFING

Digital evidence, explained for litigators.

One email a week on forensic method, digital evidence, and expert testimony — written for counsel, not for technicians. No pitches.

DOUBLE OPT-IN · UNSUBSCRIBE ANY TIME · PRIVACY POLICY

  • Can This Artifact Prove That?

    Start from the claim rather than the artifact: which records bear on it, and what no combination of them establishes.

  • Computer forensics

    The examination this artifact is collected and analysed in, scoped to a matter and reported so it can be tested.

  • The artifact index

    All 36 entries, grouped by what they bear on and filterable by platform.

  • Daubert and digital evidence

    Why an opinion stated one level too strongly is an admissibility problem rather than a point for cross-examination.

← BACK TO THE ARTIFACT INDEX

Attorney advertising / expert services. This page describes forensic artifacts and the procedural rules that govern expert evidence in general terms. Artifact behaviour varies by operating-system version, build, and configuration, and every observation has to be verified against the system actually in front of you. Nothing here is legal advice, and it is not a substitute for checking the rules, standing orders, and case law of your own forum.