#DFIR realizations - ctime isn't the creation date on Linux systems but the "status change" date - strings -el includes wide formatted strings - each registry key has a modification time stamp that isn't visible in regedit.exe What was yours?
15
45
160
Replying to @cyb3rops @Shpantzer
- $I32 date fields in directory indices - MFT slack

Sep 5, 2022 · 5:10 PM UTC

1