timestamp, conversi...
 
Notifications
Clear all

timestamp, conversion from hex?

19 Posts
7 Users
0 Reactions
4,902 Views
(@forenz)
Eminent Member
Joined: 18 years ago
Posts: 47
Topic starter  

They are 32bit Unix timestamps.

Thanks again, but how did you know that these were 32bit Unix timestamps? there are other decode formats i can set the program to and it will still decode to a date. How did you know which format to trust?


   
ReplyQuote
keydet89
(@keydet89)
Famed Member
Joined: 21 years ago
Posts: 3568
 

> how did you know that these were 32bit Unix timestamps?

That comes in part from knowing the structure of the Event Log records.


   
ReplyQuote
(@forenz)
Eminent Member
Joined: 18 years ago
Posts: 47
Topic starter  

Hows that?

I do know the structure of the event log records.


   
ReplyQuote
keydet89
(@keydet89)
Famed Member
Joined: 21 years ago
Posts: 3568
 

> Hows that?
>
> I do know the structure of the event log records.

Okay, then…it sounds like you just answered your own question! 😉

Here's some documentation from MS
http//msdn2.microsoft.com/en-gb/library/aa363646.aspx

If you read it, you'll see that the timestamps are both 4-byte values and they meet the definition of "32bit Unix timestamps".

I guess maybe I'm missing something, then…you say that you know the structure and format of the event records, but you're asking "how did you know that these were 32bit Unix timestamps?". I mean, it's right there in the structure documentation.

I must be completely off-base here and completely misunderstanding what you're asking…sorry…

H


   
ReplyQuote
(@forenz)
Eminent Member
Joined: 18 years ago
Posts: 47
Topic starter  

Its ok


   
ReplyQuote
keydet89
(@keydet89)
Famed Member
Joined: 21 years ago
Posts: 3568
 

Its ok

What does that mean?


   
ReplyQuote
 kern
(@kern)
Trusted Member
Joined: 20 years ago
Posts: 67
 

I must be completely off-base here and completely misunderstanding what you're asking…sorry…

its ok

maybe he's accepting your apology lol


   
ReplyQuote
keydet89
(@keydet89)
Famed Member
Joined: 21 years ago
Posts: 3568
 

Maybe…but it might help more if he were to clear up some things…


   
ReplyQuote
(@teenwolf)
New Member
Joined: 15 years ago
Posts: 3
 

I wrote a similar program, it decodes various formats, except the program is command line. You can download it at

www.live-forensics.com


   
ReplyQuote
Page 2 / 2
Share: