Module 9 - Timeline Analysis
Module 9 - Timeline Analysis
Introduction
9.3. Approaches
In the past, the focus was only on the file system metadata
details; now, it has become something different with more
data to look at.
You will notice that they are all normal operations done by system
administrators all the time.
So the MACB time meanings by most common file systems could be seen
as:
File system m a c b
FAT Written Accessed Not available File created
• System name
• Host name
• IP Address
• MAC Address
• Brief description
• Sufficient information to evaluate significance
• Can include spaces and special characters
• Just no “|”s
The first one is using the directory export listing option in FTK
Imager.
Remember, if you don’t know what time zone the system was
using, you must check the Windows Registry for that.
You can create a custom file with the .lst file extension
(e.g. custom.lst) and add all the required plugins to be
applied by log2timeline.