File created date i...
 
Notifications
Clear all

File created date issue

5 Posts
5 Users
0 Reactions
557 Views
(@swordfish)
New Member
Joined: 16 years ago
Posts: 3
Topic starter  

Is there any way to find if a word document was created recently just by changing the comptuer date back to last year. Normally when you change the computer date to 11/11/2008 and create a file then file creation date is 11/11/2008, and once you change you compter date back to recent time, the file creation date is still 11/11/2008.


   
Quote
(@kovar)
Prominent Member
Joined: 18 years ago
Posts: 805
 

Greetings,

If you have access to the computer that was used to create the documents, there will be artifacts indicating that the clock was changed.

If you have access to the file system, you could run Mark Menz's MFT Ripper and check the suspect file's inode against other files that were created around the same time. The inodes are allocated sequentially, so if you sort the files by creation date they should also line up by inode value. If they don't, it is a strong indication that the system's time was modified.

(Someone please check me on the above. I cannot find the paper or blog post describing this and am working from memory.)

-David


   
ReplyQuote
(@patrick4n6)
Honorable Member
Joined: 16 years ago
Posts: 650
 

The search indexing system for Office docs has a log file. I can't remember off the top of my head where it's located, but if you find non-sequential dates in the fast find indexer log file, that can indicate changing of the system date to falsify metadata.


   
ReplyQuote
Wardy
(@wardy)
Estimable Member
Joined: 20 years ago
Posts: 149
 

Kovar, the record numbers are created sequentially.

You're explanation is good, I'd like to expand slightly though.

If you delete a file (entry 1000) and it's entry is reused by a new file dated last year, the inconsistency in the sequence of creation dates will be obvious. The record number will still be 1000 though and will not have incremented as it is using entry 1000 of the MFT.

If you were to create a new file and it takes a new slot in the MFT (say entry 9999) and it's created date is some time last year, again, the inconsistency will be obvious.


   
ReplyQuote
(@yunus)
Estimable Member
Joined: 17 years ago
Posts: 178
 

You will never know for sure whether the user has put the clock back. He does not have to do it to change the dates, just a small software can change dates as you wish.

So, even if you guarantee that he has not played with the computer clock, there is still the possibility that he may have changed it anyways.


   
ReplyQuote
Share: