Live Linux Forensics training coming up @WWHackinFest Deadwood! Let's do some daily Linux Forensics trivia as a lead-up! wildwesthackinfest.com/deadw…
34
50
2
95
Daily Linux Forensics Trivia #34 [last daily trivia before @WWHackinFest!] - How are atimes handled by default in EXT?

Oct 9, 2022 · 2:39 PM UTC

3
1
3
Oh come on. If you know me at all, you knew I would end on a file systems question!
1
3
Trivia Answer #34 - By default EXT uses "relatime" ("relative atimes") which means that atimes are only updated if the mtime on the file is newer than the atime at the moment the file is read.
1
1
2
Note that under "relatime" atimes will also be updated if the current atime is more than 24hrs old. The upshot is that atime often indicates the FIRST time a program is executed during an incident, rather than the last time as we would infer when atimes were updated every access.
1
1
Hmm, don't fully remember, but I thought it's updated when ctime needs to be updated or otherwise after 24 hours