Summary

In this chapter, we looked at time-related attributions on different filesystems, how to build a timeline with TSK and with the Plaso framework.

In the next chapter, we will cover how to analyze dates on the NTFS and FAT filesystems. We will continue to work with TSK and study other utilities from TSK.

Get Practical Windows Forensics now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.