Hi,
One of my friends Sandy asked me about the possibility of completely change MACE timestamps. As everybody knows that some tools could change MAC timestamps only. I told her that a tool whose name is "Timestomp" could change MACE timestamps,including Entry Modified Time. She was very surprise and ask me how to use "Timestomp". You guy could take a look at my blog
http//
Couple days later she asked me what if some suspect use Timestomp to change MACE timestamps, how could I figure it out? Fortunately, there are two kinds of timestamps in MFT. They are Standard info and Filename info attributes. I dump an MFT to csv and you could see them clearly. Even Timestomp could change MACE timestamps, it could only change Standard info attributes, not including Filename info attributes. So we could take a look at MFT dump results and see if there is any abnormal timestamps between those two timestamp attributes.
Would this tool have made any difference to the investigation of those timestamps on that volume https://
Would this tool have made any difference to the investigation of those timestamps on that volume https://
github.com/jschicht/SetMace ?
That one seems a lot like a blow below the belt ? 😯
roll
jaclaz
Or a hex editor in the right hands.