QuestionQ268

Tools/Systems/Programs

On an NTFS file system, which of the following tools can a forensic investigator use to identify timestomping of evidence files?

  • A Exiv2
  • B analyzeMFT
  • C Timestomp
  • D wbStego
Explanation

NTFS timestomping can be detected by examining timestamps recorded in Master File Table metadata, including inconsistencies between the $STANDARD_INFORMATION and $FILE_NAME attributes. analyzeMFT parses MFT records and reports those timestamps, supporting that analysis.

Community Discussion

No comments yet. Be the first to start the discussion!