MAC times and Scann...
 
Notifications
Clear all

MAC times and Scanners

4 Posts
4 Users
0 Reactions
401 Views
(@mwade)
Trusted Member
Joined: 18 years ago
Posts: 77
Topic starter  

Hello,

Can anyone tell me how one deals with interpretting access times on compromised systems when the user runs (or admins run) malware scanners on the system daily. If the scanner touches every file I am assuming that it will change the access time of every file on the system. Doesn't that create a challenge when trying to use MAC times, specifically the "A" times.

Thanks,

Mark


   
Quote
(@cosimo)
Eminent Member
Joined: 19 years ago
Posts: 20
 

Yes, of course it modifies the 'A' times. You may try to distinguish between files touched by the scanner and those touched by the user by inspecting the log file that the scanner might have generated, and the rules defining which files/folders are scanned.


   
ReplyQuote
keydet89
(@keydet89)
Famed Member
Joined: 21 years ago
Posts: 3568
 

Mark,

This happens all the time. In fact, by default, Vista does not update last access times on files. This is why alternative methods of forensic analysis are required.

H


   
ReplyQuote
 Earn
(@earn)
Estimable Member
Joined: 20 years ago
Posts: 146
 

Create and Modify dates are usually what I look at. Access is usually not something you can put too much trust into.


   
ReplyQuote
Share: