There are not a lot of times where one cab be 100% sure that the MAC times have not been altered.
Usually, you would want to take other events and build it around your main evidence. email, chat logs, installing of windows service packs, internet history, p2p, etc.
In 2 of my evidences i cannot view the sys.evt files, event viewer says they are corrupted, the rest 4 are fine.
Could this mean something ?
armresl, your answer i am afraid is to general.
Lots of files in Encase, although they are e-mails or documents they appear with different strange names .gif, .jpg etc.
Why is that happenning and how can i bring them back to they original form ?
Thanx
Sounds like you need to take a Encase training class.
Lots of files in Encase, although they are e-mails or documents they appear with different strange names .gif, .jpg etc.
Why is that happenning and how can i bring them back to they original form ?
Thanx
Not quite sure, but have you run the "Verify File Signatures" option under the search tab?