Windows Time Rule for Digital Forensic

There are some common rules for windows time rule for $Standard_Information and $Filename. Here is the table for those common rules.

This below table (created by SANS) is the rule for MACB/E (Modified , Access, Create/Change, and Birth/Entry) timestamps.

Usually, $FILENAME information is hardly modified/timestomped. So this information can be useful for doing a forensic for Windows file.


We are teams that have the same hobbies in Information Technologies and have experienced in many fields regarding Information Technologies .

Recent Articles

Leave a Reply

avatar
  Subscribe  
Notify of