±Forensic Focus Partners

Become an advertising partner

±Your Account


Username
Password

Forgotten password/username?

Site Members:

New Today: 2 Overall: 35770
New Yesterday: 6 Visitors: 138

±Follow Forensic Focus

Forensic Focus Facebook PageForensic Focus on TwitterForensic Focus LinkedIn GroupForensic Focus YouTube Channel

RSS feeds: News Forums Articles

±Latest Articles

±Latest Videos

±Latest Jobs

Even more SetMace

Computer forensics discussion. Please ensure that your post is not better suited to one of the forums below (if it is, please post it there instead!)
Reply to topicReply to topic Printer Friendly Page
Forum FAQSearchView unanswered posts
 
  

joakims
Senior Member
 

Even more SetMace

Post Posted: Aug 05, 14 04:17

Just brushing some dust off the old topic of timestamp manipulation on NTFS. Version 1.0.0.10 of SetMace now implements a kernel mode driver, thus removing a lot of the restrictions put on the previous versions.

reboot.pro/topic/15960-setmace/

Now I think the project has reached a dead end, unless someone else wants to take it further into handling the raw structures of shadow copies..
_________________
Joakim Schicht

github.com/jschicht 
 
  

joakims
Senior Member
 

Re: Even more SetMace

Post Posted: Aug 16, 14 20:51

- joakims

Now I think the project has reached a dead end, unless someone else wants to take it further into handling the raw structures of shadow copies..


And then a few more fixes was done, to support MFT record size of 4096 bytes, dumping of timestamps from parent's INDX, as well as fixing an issue with synchronization of $STANDARD_INFORMATION timestamps and those found in the INDX of the parent.

Regarding the latter, it turned out a simple call to NtQueryInformationFile would force Windows to synchronize them.
_________________
Joakim Schicht

github.com/jschicht 
 
  

joakims
Senior Member
 

Re: Even more SetMace

Post Posted: Sep 07, 14 02:30

Added support for shadow copy timestamp modification, among other things. Now, also being a PoC for showing how to modify data within a Shadow Copy.
_________________
Joakim Schicht

github.com/jschicht 
 

Page 1 of 1