Observed arrival · 2026-09-28
A browser-based NTFS journal parser for incident response
LogFileParser reconstructs file creations, renames, deletions, and timestamp changes from an NTFS transaction journal.
○Open
⊠Login
$Paid
†Ads
✦Pretty
●Pro
◎Niche
◉Human
⚑Risk
ƒJS
- For
- DFIR analysts investigating NTFS file activity
- Worth noticing
- The page says each reconstructed event links back to its raw log records, and offers a synthetic intrusion sample.
Field notes
The parser accepts folders and ZIP triage collections as well as selected files, and the page explains how to collect the journal and MFT with KAPE, Velociraptor, FTK Imager, or The Sleuth Kit. A matching MFT is needed to resolve references into full paths. The offered sample is labeled synthetic and uses a fictional intrusion; the page also says parsing runs locally through WebAssembly.
Observed signals
Read the marks
Editorial observations of this landing page, not a rating.
○OpenPublic substance visible
✦PrettyNotable craft visible
●ProPolished or operationally mature
◎NicheUnusually specific use
ƒJavaScriptBrowser-side code central
One card from the complete issue