What is the NTFS USN Journal?
The Update Sequence Number Journal is a change log that NTFS maintains for every file create, delete, rename and metadata modification on a volume. It lives in the alternate data stream \$Extend\$UsnJrnl:$J and is one of the richest sources of timeline evidence in Windows forensics.