Challenge: Back to the Cereal

Course Content
Blue Team POV: System Analysis
> In this challenge, you will analyze a compromised system $MFT file related to attacks targeting NTFS timestamps. This challenge aims to showcase the importance of the $MFT file in a forensics investigation and the importance of timestamps to distinguish abnormal vs. normal activity.