Mobile QR Code QR CODE

2025

Reject Ratio

81.5%

References

1 
F. Y. Loumachi , M. C. Ghanem , M. A. Ferrag , Advancing cyber incident timeline analysis through retrieval-augmented generation and large language models, Computers, Vol. 14, No. 2, Art. no. 67, 2025DOI
2 
C. Swenson , R. Phillips , S. Shenoi , Applying the Biba integrity model to evidence management, Advances in Digital Forensics III, Vol. 242, pp. 231-244, 2007DOI
3 
S. Bhandari , V. Jusas , An abstraction-based approach for reconstruction of timeline in digital forensics, Symmetry, Vol. 12, No. 1, Art. no. 104, 2020DOI
4 
B. Carrier , E. Spafford , An event-based digital forensic investigation framework, Digital Investigation, 2004Google Search
5 
D. Jang , G.-J. Ahn , H. Hwang , K. Kim , Understanding anti-forensic techniques with timestamp manipulation, Proceedings of the 17th International Conference on Information Reuse and Integration (IRI), pp. 609-614, 2016DOI
6 
J.-P. A. Yaacoub , H. N. Noura , O. Salman , A. Chehab , Digital forensics vs. anti-digital forensics: Techniques, limitations and recommendations, arXiv preprint arXiv:2103.17028, 2021DOI
7 
C. Vanini , C. Hargreaves , F. Breitinger , Evaluating tamper resistance of digital forensic artifacts during event reconstruction, Digital Threats: Research and Practice, Vol. 6, No. 4, pp. 1-16, 2025DOI
8 
J. Oh , S. Lee , H. Hwang , Forensic detection of timestamp manipulation for digital forensic investigation, IEEE Access, Vol. 12, pp. 72544-72565, 2024DOI
9 
Timestomp (T1070.006), MITRE ATT&CK, [Online]. Available: https://attack.mitre.org/ techniques/T1070/006/. Accessed: Sep. 21, 2025., 2025URL
10 
MITRE ATT&CK: Adversarial tactics, techniques, and common knowledge, MITRE ATT&CK, [Online]. Available: https://attack.mitre.org/. Accessed: Sep. 21, 2025., 2025URL
11 
C. Hargreaves , J. Patterson , An automated timeline reconstruction approach for digital forensic investigations, Digital Investigation, Vol. 9, pp. S69-S79, 2012DOI
12 
M. J. Hannon , Metadata in civil and criminal discovery–Part II, The Computer & Internet Lawyer, Vol. 35, 2018Google Search
13 
R. Russon , Y. Fledel , NTFS documentation, Recuperado el, Vol. 1, pp. 2, 2004Google Search
14 
B. Carrier , File System Forensic Analysis, Addison-Wesley Professional, 2005Google Search
15 
X. Ding , H. Zou , Reliable time based forensics in NTFS, School of Software, Shanghai Jiao Tong University, pp. 1-2, 2010Google Search
16 
A. Ðuranec , D. Topolčić , K. Hausknecht , D. Delija , Investigating file use and knowledge with Windows 10 artifacts, Proceedings of the 2019 42nd International Convention on Information and Communication Technology, Electronics and Microelectronics (MIPRO), pp. 1213-1218, 2019DOI
17 
A. Budhrani , U. Singh , B. Singh , Analysis of Windows 11 link file artifact for evidence gathering, Proceedings of the 2022 International Conference on Futuristic Technologies (INCOFT), pp. 1-6, 2022DOI
18 
N. Hashim , I. Sutherland , An architecture for the forensic analysis of Windows system artifacts, Digital Forensics and Cyber Crime, pp. 120-128, 2011DOI
19 
Master file table and NTFS metadata files, Microsoft, [Online]. Available: https://learn.microsoft.com/en-us/windows/win32/fileio/master-file-table. Accessed: Sep. 24, 2025., 2025URL
20 
X. Ding , H. Zou , Reliable time based forensics in NTFS, School of Software, Shanghai Jiao Tong University, pp. 1-2, 2010Google Search
21 
M. Kangas , Timestamp analysis in Windows OS file systems, 2025Google Search
22 
J. Oh , S. Lee , H. Hwang , Forensic recovery of file system metadata for digital forensic investigation, IEEE Access, Vol. 10, pp. 111591-111606, 2022DOI
23 
J. Oh , S. Lee , H. Hwang , NTFS data tracker: Tracking file data history based on $LogFile, Forensic Science International: Digital Investigation, Vol. 39, Art. no. 301309, 2021DOI
24 
fsutil usn–Manage the USN change journal, Microsoft, [Online]. Available: https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/fsutil-usn. Access- ed: Sep. 24, 2025., 2024URL
25 
GetFileTime function (fileapi.h)–Win32 apps, Microsoft, [Online]. Available: https://learn.microsoft.com/en-us/windows/win32/api/fileapi/nf-fileapi-getfiletime. Accessed: Sep. 15, 2025., 2022URL
26 
SetFileTime function (fileapi.h)–Win32 apps, Microsoft, [Online]. Available: https://learn.microsoft.com/en-us/windows/win32/api/fileapi/nf-fileapi-setfiletime. Accessed: Sep. 15, 2025., 2022URL
27 
H. Carvey , Windows Forensic Analysis Toolkit: Advanced Analysis Techniques for Windows 8, Elsevier, 2014Google Search
28 
A. A. Bahjat , J. Jones , Deleted file fragment dating by analysis of allocated neighbors, Digital Investigation, Vol. 28, pp. S60-S67, 2019DOI
29 
G.-S. Cho , A digital forensic analysis of timestamp change tools for Windows NTFS, Journal of the Korea Society of Computer and Information, Vol. 24, No. 9, pp. 51-58, 2019DOI
30 
S. Neuner , A. G. Voyiatzis , M. Schmiedecker , E. R. Weippl , Timestamp hiccups: Detecting manipulated filesystem timestamps on NTFS, Proceedings of the 12th International Conference on Availability, Reliability and Security, pp. 1-6, 2017DOI
31 
FileTouch, Available: http://www.softtreetech.com/24x7/archive/47.htm. Accessed: Sep. 15, 2025., 2025URL
32 
chtime, [Online]. Available: https://github.com/Loadmaster/chtime-win32. Accessed: Sep. 15, 2025., 2025URL
33 
S. Küng , SKTimeStamp, [Online]. Available: https://tools.stefankueng.com/SKTimeStamp.html. Accessed: Sep. 15, 2025., 2025URL
34 
N. Hrg , NewFileTime, [Online]. Available: https://www.softwareok.com/?seite=Microsoft/New FileTime. Accessed: Sep. 15, 2025., 2025URL
35 
N. Sofer , Bulk File Changer, [Online]. Available: https://www.nirsoft.net/utils/bulk_file_changer.html. Accessed: Sep. 15, 2025., 2025URL
36 
eXpress TimeStamp Toucher, [Online]. Available: https://www.softpedia.com/get/System/File-Management/TimeStamp-Toucher.shtml. Accessed: Sep. 15, 2025., 2025URL
37 
G.-S. Cho , Data hiding in NTFS timestamps for anti-forensics, The International Journal of Internet, Broadcasting and Communication, Vol. 8, No. 3, pp. 31-40, 2016DOI
38 
H. Kwon , S. Lee , Digital forensic analysis of timestamp change tools: An anti-forensics perspective, Forensic Science International: Digital Investigation, Vol. 33, Art. no. 301013, 2020Google Search
39 
S. Galhuber , R. Luh , Time for truth: Forensic analysis of NTFS timestamps, Proceedings of the 16th International Conference on Availability, Reliability and Security (ARES 2021), pp. 1-10, 2021DOI
40 
J. Foster , V. Liu , Catch me, if you can..., Black Hat USA 2005 Presentation, 2005Google Search
41 
ZwSetInformationFile function (wdm.h), Microsoft, [Online]. Available: https://learn.microsoft.com/en-us/windows-hardware/drivers/ddi/wdm/nf-wdm-zwsetinformationfile. Accessed: Jan. 8, 2026., 2023URL
42 
NtSetInformationFile function, Microsoft, [Online]. Available: https://learn.micro soft.com/en-us/windows-hardware/drivers/ddi/ntifs/nf-ntifs-ntsetinformationfile. Accessed: Sep. 15, 2025., 2025URL
43 
M. Geiger , S. Zhu , Timestamp tampering and forensic detection, Computer and Information Security Handbook, pp. 411-432, 2017Google Search
44 
FILE_BASIC_INFORMATION structure (wdm.h), Microsoft, [Online]. Available: https://learn.microsoft.com/en-us/windows-hardware/drivers/ddi/wdm/ns-wdm-_file_basic_information. Accessed: Jan. 9, 2026., 2024URL
45 
J. Bouma , H. Jonker , V. van der Meer , E. Van Den Aker , Reconstructing timelines: From NTFS timestamps to file histories, Proceedings of the 18th International Conference on Availability, Reliability and Security (ARES '23), pp. 1-9, 2023DOI
46 
W. Minnaard , Timestomping NTFS, Master's thesis, University of Amsterdam, Amsterdam, The Netherlands, 2014Google Search
47 
Date forgery analysis and timestamp resolution, [Online]. Available: https://www.meridiandiscovery.com/articles/ date-forgery-analysis-timestamp-resolution/. Ac- cessed: Sep. 27, 2025., 2016URL
48 
B. Lim , nTimetools: Timestomper and timestamp checker with nanosecond accuracy for NTFS volumes, [Online]. Available: https://github.com/limbenjamin/nTimetools. Accessed: Nov. 11, 2020., 2020URL
49 
D. Palmbach , F. Breitinger , Artifacts for detecting timestamp manipulation in NTFS on Windows and their reliability, Forensic Science International: Digital Investigation, Vol. 32, Art. no. 300920, 2020DOI
50 
J. Schicht , SetMACE v1.0.0.6, Reboot Pro File Repository, [Online]. Available: https://github.com/jschicht/SetMACE. Version 1.0.0.6; release date un- known. Accessed: Sep. 20, 2025.URL
51 
KB942448: Changes to the file system and to the storage stack to restrict direct disk access and direct volume access in Windows Vista and in Windows Server 2008, Microsoft, [Online]. Available: https://mskb.pkisolutions.com/kb/942448. Accessed: Jan. 8, 2026., 2008URL
52 
APT29, MITRE ATT&CK, [Online]. Available: https://attack.mitre.org/groups/G0016. Accessed: Dec. 27, 2025., 2025URL
53 
UNC3524: Eye spy on your email, [Online]. Available: https://www.mandiant.com/resources/blog/unc3524- eye-spy-on-your-email. Accessed: Dec. 25, 2025., 2022URL
54 
Supply chain compromise: Detecting APT activity from known TTPs, [On- line]. Available: https://www.cisa.gov/sites/default/files/publications/Supply_Chain_Compromise_Detecting_APT_Activity_from_known_TTPs.pdf. Accessed: Dec. 26, 2025., 2021URL
55 
Deep dive into the Solorigate second-stage activation: From SUNBURST to TEARDROP and Raindrop, Microsoft Security Blog, [Online]. Available: https://www.microsoft.com/en-us/security/blog/2021/01/20/deep-dive-into-the- solorigate-second-stage-activation-from-sunburst-to-teardrop-and-raindrop/. Accessed: Dec. 26, 2025., 2021URL
56 
APT32, MITRE ATT&CK, [Online]. Available: https://attack.mitre.org/groups/G0050. Accessed: Dec. 27, 2025., 2024URL
57 
N. Carr , Cyber espionage is alive and well: APT32 and the threat to global corporations, [On- line]. Available: https://cloud.google.com/blog/topics/threat-intelligence/cyber-espionage-apt32/. Accessed: Dec. 25, 2025., 2017URL
58 
R. Dumont , Fake or fake: Keeping up with OceanLotus decoys, [Online]. Available: https://www.welivesecurity.com/2019/03/20/fake-or-fake-keeping-up-with-oceanlotus-decoys/. Ac- cessed: Dec. 25, 2025., 2019URL
59 
R. Dumont , OceanLotus: macOS malware update, [Online]. Available: https://www.welivesecurity.com/2019/04/09/oceanlotus- macos-malware-update/. Accessed: Dec. 25, 2025., 2019URL
60 
H. Carvey , Windows Registry Forensics: Advanced Digital Forensic Analysis of the Windows Registry, Elsevier, 2011Google Search
61 
Lazarus group, MITRE ATT&CK, [Online]. Available: https://attack.mitre.org/groups/G0032. Accessed: Dec. 27, 2025., 2025URL
62 
Operation blockbuster: Unraveling the long thread of the Sony attack, [Online]. Available: https://www.operationblockbuster.com/resources/. Accessed: Dec. 26, 2025., 2016URL
63 
Operation blockbuster: Destructive malware report, [On- line]. Available: https://www.operationblockbuster.com/resources/. Accessed: Dec. 26, 2025., 2016URL
64 
Operation blockbuster: Loaders, installers and uninstallers report, [Online]. Available: https://www.operationblockbuster.com/resources/. Accessed: Dec. 26, 2025., 2016URL
65 
Kimsuky group's APT attacks using CHM (targeting internal documents of specific organizations), ASEC Blog, [Online]. Available: https://asec.ahnlab.com/en/48223/. Accessed: Dec. 26, 2025., 2023URL
66 
Chimera, MITRE ATT&CK, [Online]. Available: https://attack.mitre.org/groups/G0114. Accessed: Dec. 27, 2025., 2024URL
67 
W. Jansen , Abusing cloud services to fly under the radar, [Online]. Available: https://web.archive.org/web/20230218064220/https://research.nccgroup.com/2021/01/12/abusing-cloud-services-to-fly-under-the-radar/. Accessed: Jan. 8, 2026., 2021URL
68 
N. Shashidhar , D. Novak , Digital forensic analysis on prefetch files, International Journal of Information Security Science, Vol. 4, No. 2, pp. 39-46, 2015Google Search
69 
Windows forensic analysis evidence poster, Digital Forensics and Incident Response (DFIR), [Online]. Available: https://www.sans.org/posters/windows-forensic-analysis/., 2022URL
70 
G.-S. Cho , A computer forensic method for detecting timestamp forgery in NTFS, Computers & Security, Vol. 34, pp. 36-46, 2013DOI
71 
J. Bang , B. Yoo , S. Lee , Analysis of changes in file time attributes with file manipulation, Digital Investigation, Vol. 7, No. 3-4, pp. 135-144, 2011DOI
72 
D.-Y. Kao , Forensic exchange analysis of contact artifacts on data hiding timestamps, Applied Sciences, Vol. 10, No. 13, Art. no. 4686, 2020DOI
73 
File times–Win32 apps, Microsoft, [Online]. Available: https://learn.microsoft.com/en-us/windows/win32/sysinfo/file-times. Accessed: Sep. 27, 2025., 2021URL
74 
ntfs-usnjrnl Command Documentation, 2022Google Search
75 
READ_USN_JOURNAL_DATA_V0 structure, Microsoft, [Online]. Available: https://learn.microsoft.com/en-us/windows/win32/api/winioctl/ns-winioctl-read_usn_journal_data_v0. Accessed: Sep. 27, 2025., 2018URL
76 
Info-ZIP application note (appnote_iz.txt), [Online]. Available: https://libzip.org/specifications/appnote_iz.txt. Accessed: Aug. 28, 2025., 2025URL
77 
Restore files and directories–Security policy setting, Microsoft, [Online]. Available: https://learn.microsoft.com/en-us/previous-versions/window s/it-pro/windows-10/security/threat-protection/secur ity-policy-settings/restore-files-and-directories. Accessed: Aug. 28, 2025., 2025URL
78 
J. Song , H.-S. Lee , A design of timestamp manipulation detection method using storage performance in NTFS, Journal of Internet of Things and Convergence, Vol. 9, No. 6, pp. 23-28, 2023DOI
79 
A. Mohamed , C. Khalid , Detection of timestamps tampering in NTFS using machine learning, Procedia Computer Science, Vol. 160, pp. 778-784, 2019DOI
80 
J. Oh , A practical approach to detecting file timestamp manipulation for digital forensic investigations, Expert Systems with Applications, Vol. 293, Art. no. 128630, 2025DOI
81 
D. Gunning , D. W. Aha , DARPA's explainable artificial intelligence (XAI) program, AI Magazine, Vol. 40, No. 2, pp. 44-58, 2019DOI