Overview
Syllabus
Intro
Windows Timelines in Minutes
What is this talk about?
Why should you care?
5 minute NTFS tutorial (cont.)
Part of the MFT entry for a root directory
More about NTFS Timestamps
Extract timestamp info
MACR retrieveal script overview
Create a database
Build that database
Create the table
Load the table from CSV file
Create & Populate timeline table
Run all the querries you want
Script to print a timeline
Example run of print-timeline.sh
Optional: Import into LibreOffice Calc
Viewing in Calc
Script to print timeline for each file
Example run of print-file-timeline.sh
Understanding Timestamps
Copying a File
Access a File
Modify a File (save contents)
Delete a File
Rename a File
Move a File (same volume)
Move a File (new volume)
Summary