nc.exe
:$MFT
for changes - first of, dumping the $MFT
:nc.exe
record and check its timestamps:fnCreateTime
did not get updated:$STANDARD_INFO
and $FILE_NAME
times during the investigation to have a better chance at detecting timestomping.fnCreateTime
timestamp would inherit the timestamp from siCreateTime
: