How can a forensic investigator detect timestomping on a Windows NTFS volume?
-
A
By comparing file MD5 hashes against known-good databases
-
B
By comparing $MFT timestamps against $LogFile and $UsnJrnl entries for inconsistencies
-
C
By running a full antivirus scan on the volume
-
D
By capturing and analyzing live network traffic logs