Timestamps collisions of Windows Analysis

by Igor Mikhaylov2017-02-25

In considering civil and criminal cases, the operating system installation date can play an important role. Sometimes the attacker will try to hide the data, so the safest is to format and reinstall it. Thus Marie DeGratsiya checked Windows, and more precisely the date of installation. Check the basic information like the date of installation and can help prioritize the examiner systems, you must examine and verify evidence of looting problems.


As a result, Windows checks and set the date Marie led a working hypothesis that that Feature update for Windows 10, 1607 updates the version of the Windows installation and removal of logs. Nevertheless, this is a lie, as Windows, as it will reflect the date of the original installation date, before it was cloned.



