#DFIR realizations
- ctime isn't the creation date on Linux systems but the "status change" date
- strings -el includes wide formatted strings
- each registry key has a modification time stamp that isn't visible in regedit.exe
What was yours?
15
45
160
- $I32 date fields in directory indices
- MFT slack
Sep 5, 2022 · 5:10 PM UTC
1

