Taking instructions now — the first conversation is freeExhibits posted in from anywhere in the UK, or handed in at ten drop-off pointsQuicker still, give us a ring:0800 6890668
FDRForensic Data Recovery 0800 6890668 Price my job
FDR / What the evidence can show / Mass deletion and the USN journal

USN journal · change journal · mass deletion · timestamped events · demand letter

Mass deletion and the USN journal. Windows keeps a running journal of every file created, renamed and deleted; a mass deletion shows up in it as a dense burst at a particular time.

Beneath the familiar file system, Windows keeps a running change journal, the USN journal, that records every create, rename and delete as a timestamped entry. For ordinary use it is invisible housekeeping. For a dispute it is a precise record of deletion, because a mass deletion, someone removing hundreds or thousands of files at once, appears in the journal as a dense burst of delete entries, all within a short window, each stamped with its time. That lets an examination state, with precision, that a large number of files in named folders were deleted between two times on a particular day, and, crucially, to compare that against the dates that matter: a solicitor's demand letter, a resignation, a board meeting. A mass deletion the morning after a demand letter is exactly the kind of fact the journal captures. The report sets out the deletion event factually; it shows the account under which the deletions occurred and when, not the person at the keyboard, and it is read alongside what the deleted files recovery could retrieve.

Owner-only, authority requiredFree first conversationStandard report £800 + VATWe say what it cannot prove

Rather talk it through? An engineer answers the bench line
0800 6890668

Before anything else: stop using the device, and do not let anyone have a look at it. Every time a computer is switched on and used, the very artefacts an examination relies on, the timeline, the recently-opened lists, the deleted-file space, are overwritten a little more. Do not reinstall, do not run recovery software, do not let IT open it to check, and keep it powered off. Preserve it as it is, record who has held it, and send it with the authority documents we ask for. If proceedings are contemplated, the duty to preserve evidence has already begun.

How the journal captures a deletion event, and what it proves.

The USN journal (the Update Sequence Number journal) is a feature of the NTFS file system that logs changes to files and folders, each entry recording the file, the type of change, create, rename, delete and others, and the time. It exists so that applications like search indexers and backup tools can find out what has changed without scanning the whole disk, and it runs continuously in the background.

Because it logs deletions with times, it is the artefact that captures a mass-deletion event. When someone deletes a large number of files at once, the journal fills with delete entries clustered in a short window, and an examination can report how many files, in which folders, were deleted between which times on which day. Against the ordinary background of a few changes here and there, a burst of hundreds or thousands of deletions stands out sharply.

The evidential force is in the comparison with key dates. The journal lets the deletion be placed precisely in time, so it can be set beside the date of a demand letter, a resignation or a board decision, and a deletion that follows such an event closely is a fact the report can state plainly. The limits are the usual ones: the journal records the user account under which the deletions occurred, not the person at the keyboard, and it shows that files were deleted, with the deleted-file recovery showing how many could be retrieved.

What it records, and what it means.

Describe your situation →
What is recorded Where it comes from What it shows, and does not
A mass deletion, placed in timeThe USN journal's delete entriesHow many files, in which folders, between which times
The deletion against a key dateJournal times compared with dates you provideThe timing; not the motive
Which account the deletions ran underThe journal and the Security logThe account; not the person at the keyboard
How much was recoverableDeleted-file recovery on the same exhibitWhat was recovered; overwritten and wiped files are gone

From the exhibit arriving to the report.

Work we have closed →
01

The first conversation, and the authority check Free

Tell us the situation, who owns the device, and what you need to know. We tell you whether it is a job we can take on, what authority we will need, and whether the standard report answers your questions or an expert report is called for. That conversation is free, and some enquiries end there, because we will not take work we cannot lawfully or honestly do.

FreeOwner-only; authority established firstThe honest answer about what is possible
02

Imaging behind a write blocker, and the hashes

When the exhibit arrives, your authority is checked, the device is logged and photographed, and the drive is connected through a hardware write blocker and imaged bit for bit. MD5 and SHA-256 hashes of the source and the image are computed and verified, so the copy is provably identical. Nothing is examined on the original; every later step is done on the verified image.

Bit-for-bit, behind a write blockerMD5 and SHA-256, verifiedThe original never altered
03

The examination, on the image

The image is examined for the artefacts your questions turn on: USB device history, files opened from removable media, cloud and webmail activity, deleted files and the Recycle Bin, the USN journal, program execution, email, document metadata, shadow copies, and a timeline. Findings that matter are confirmed in a second tool. The work is scoped to what you asked; material outside the scope is not reproduced.

Scoped to your questionsConfirmed in a second toolPrivate material filtered out
04

The report

The standard forensic report sets out the exhibit and its condition, the integrity record, the tools and method, and the findings by category, with a timeline, the limitations, and factual conclusions, as a self-contained report with its chain-of-custody and case-log reports. It is written in plain terms, keeps fact separate from any comment, and is suitable for internal decisions, HR processes, negotiations and solicitors. Where you need opinion evidence for court, an expert report is quoted.

Factual, tool-generated, self-containedChain-of-custody and case-log reports5–10 working days

From the bench

  • Preserve the drive; the journal has a finite size and very heavy later activity can roll old entries out, though it usually covers the relevant period.
  • Give us the key dates; the journal's value is in comparing the deletion against a demand letter or a resignation.
  • Pair it with recovery; the journal shows the deletion, the recovery shows what remains, and together they are strongest.

The USN change journal records every deletion with a time, so a mass deletion can be placed to the hour and set beside the date of a demand letter.

What helps, and what harms.

Do this much first

  • Stop using the device and keep it powered off
  • Preserve it as it is; record who has held it
  • Gather your proof of ownership or authority
  • Tell us the questions you need answered

What sets us back

  • Letting IT or anyone open it to have a look
  • Reinstalling, wiping or running recovery software
  • Carrying on using the device
  • Assuming artefacts prove who was at the keyboard
We examine devices only for the people and organisations with lawful authority over them. Before any work begins we ask for proof that the device is yours, or documented authority to have it examined: proof of ownership, a director's or HR letter for a company device with the lawful basis, a solicitor's instruction, a court order, or an executor's grant. It is a condition of the work, not a formality, and it is what keeps the examination on the right side of the Computer Misuse Act 1990. We will not access another adult's device or accounts without their consent or a court order, we will not install monitoring software or bypass anyone's security, and we do not undertake covert surveillance. A device with no proof of authority is returned unexamined.

Questions answered before you instruct.

Can you show when files were mass-deleted?

Yes, often to the hour. The NTFS change journal records every deletion with a time, so a mass deletion appears as a dense burst of entries in a short window, and the report can state how many files in which folders were deleted between which times on which day. That precision is what lets it be compared against a key date.

Why does the timing matter so much?

Because a deletion that closely follows a demand letter, a resignation or a board decision is far more significant than one at a random time, and the journal lets the deletion be placed precisely enough to make that comparison. A mass deletion the morning after a solicitor's letter is exactly what the journal captures.

Does the journal prove who deleted the files?

No. It records the user account under which the deletions occurred and when, not who was physically at the keyboard. As with every artefact, we state that limit; the timing and the surrounding evidence are what give it weight.

Can you recover the mass-deleted files?

Partly, usually. The journal shows the deletion event; the deleted-file recovery on the same exhibit shows how many of the files can be retrieved. On a hard disk much is often recoverable; on an SSD, or where a wiping tool overwrote the space, far less. The report sets out both.

What does it cost?

Journal analysis is part of the standard forensic report, £800 + VAT for a one-disk system. The first conversation is free.

The record is on the device; preserve it first.

The first conversation is free. Tell us the situation and who owns the device, and we will tell you what the evidence can show, what it cannot, and whether we can take it on. Until then, stop using the device and preserve it as it is.

0800 6890668