The Truth About Windows Explorer Timestamps
Machine-readable: Markdown · JSON API · Site index
Описание видео
In this episode, we’ll uncover how Windows Explorer really retrieves file timestamps when you browse a directory of files. Learn why these timestamps actually come from the $FILE_NAME attribute in the parent directory’s $I30 index, not from $STANDARD_INFORMATION, and how NTFS structures like $INDEX_ROOT and $INDEX_ALLOCATION make this process efficient.
*** If you enjoy this video, please consider supporting 13Cubed on Patreon at patreon.com/13cubed. ***
📖 Chapters
00:00 - Intro
01:02 - Recap of MACB Timestamps
04:52 - Recap of $I30
06:58 - Conclusion
🛠 Resources
$STANDARD_INFORMATION vs. $FILE_NAME:
https://dfir.ru/2021/01/10/standard_information-vs-file_name/
#Forensics #DigitalForensics #DFIR #ComputerForensics #WindowsForensics