What does the NTFS $LogFile record, and why is it forensically valuable?
-
A
User login events and failed authentication attempts
-
B
Transactional metadata changes to the file system, allowing reconstruction of recent file operations
-
C
Content of recently opened documents
-
D
Network connections associated with file transfers