I needed support to access $Extend/$UsnJrnl:$Jfor forensic artifact extraction.
From the ntfs-3g docs:
By default, ntfs-3g will only read the unnamed data stream.
By using the options "streams_interface=windows", with the ntfs-3g driver (not possible with lowntfs-3g), you will be able to read any named data streams, simply by specifying the stream's name after a colon. For example:
I needed support to access
$Extend/$UsnJrnl:$J
for forensic artifact extraction.From the ntfs-3g docs: