Finding the origina...
 
Notifications
Clear all

Finding the original creation date

4 Posts
3 Users
0 Reactions
428 Views
(@uc2obm)
Active Member
Joined: 17 years ago
Posts: 6
Topic starter  

Not sure if this is even possible, but you never know…a lot of smart people here 😉

I have an email (that I received) with an attachment (Word document), and I need to find the original creation date of that Word document. As you all know, once you attach a document, the creation date (for that attachment) is changed to the date when the email was created/sent.

Thanks in advance for your input and assistance.


   
Quote
keydet89
(@keydet89)
Famed Member
Joined: 21 years ago
Posts: 3568
 

Depending on the version of Word used to create the document, you may be able to extract OLE metadata

http//windowsir.blogspot.com/search?q=wmd

This is covered in the book, "Windows Forensic Analysis".


   
ReplyQuote
neddy
(@neddy)
Estimable Member
Joined: 21 years ago
Posts: 182
 

I have used a tool called metedata assistant to extract the metadata of RTF files. You may also find that the demo version of FTK will do the job for free.


   
ReplyQuote
(@uc2obm)
Active Member
Joined: 17 years ago
Posts: 6
Topic starter  

Keydet89 thanks for the link, I ran the perl script, and even thought the creation date still showed the one that was punched when it was attached to the email, it provided other metadata that will come in handy.


   
ReplyQuote
Share: