Notifications
Clear all
Topic starter
09/11/2011 4:59 am
Hi All,
Forensicating a Unix system at the moment. Using FTK 3.4 – it displays the following time stamp columns Created, Accessed, Modified. I know there is no Created time stamp for Unix – instead there should be an Inode Changed. I know how to add different column settings, however there are only Unix security feature settings – no time stamp options. Are there additional "plugins" I can download or is Created actually = Inode Changed??
Any documentation on this would be above, beyond and appreciated.
Thanks