Where file was crea...
 
Notifications
Clear all

Where file was created

3 Posts
2 Users
0 Reactions
623 Views
(@eugene_777)
Eminent Member
Joined: 8 years ago
Posts: 22
Topic starter  

Hello.
How exact to know whether the file was created on a certain PC or copied from other PC?
Some facts, e.g. GUID, SID Owner, Author can be changed depends on PC where this file was opened. Thus, they didn't give exact information where a file was created.

Thanks in advance.


   
Quote
hectic_forensics
(@hectic_forensics)
Eminent Member
Joined: 7 years ago
Posts: 40
 

If we're talking NTFS, take a look at the $Logfile and if it is active, the $UsnJrnl.$J file.

The USN journal is a great source of evidence and may allow you to track a file's history on the volume in question by its MFT file identifier.


   
ReplyQuote
(@eugene_777)
Eminent Member
Joined: 8 years ago
Posts: 22
Topic starter  

I agree with you the USN journal is a great resource of information but it will not show where a file was created. They can show that a file existed or existed in past. Maybe I'm wrong.


   
ReplyQuote
Share: