Max

5 responses to “Modify NTFS Timestamps and Cover Your Tracks With Timestomp.exe”

  1. Are there any KFF hash files for timestomp that might flag its use?

  2. I rarely comment on blogs but yours I had to stop and say Great Blog!!

  3. Hey BG, I’m pretty sure there are not. I don’t use FTK really so I can’t be certain but it looks like you can make your own pretty easily. Link (PDF)

    However, you’d be out of luck if someone brought in a packed/compressed or otherwise modified timestomp.exe into a system. One which you don’t have access to create a hash out of.

  4. Very interesting site, Hope it will always be alive!

  5. [...] information for malicious actors on the tools and methods to modify timestamps is out there already and has [...]

Leave a Reply

Archives