Okay, So another thing to think about as you're doing you're contesting work is
in the interest of covering your tracks. And we're confusing a investigator. You want to be able to perhaps modify
the attributes of the files they leave behind,
whether they are files that information have been gathering or whether it is a
a part of your tool kit
that you're using to to interrogate the system.
So what I want to do first is go to
the folder where I have my files.
Second. See, I've got in particular. I'm interested in this file here. Tools down, yaks eat.
You notice it has a,
you know, day from a few days ago.
There's some other ah
files in the same directory and that you could try to use, um,
the Times Time Command.
This lets me modify a lot of this information so I can modify the last access time, modify the creation time, the last written file, the restaurant in time, which is a modification time. Basically, I could also try to copy
the attributes of a foul that already exists.
And I can even make these changes reclusive Lee. So if I wanted to change
an entire Philidor structure from from a certain top Flubber folder all the way down all the files inside there, I could do that. And I resent the dash B the blank option, which will definitely confuse a
investigator because you're looking at that information, not understanding. Why are these dates all wrong?
Why are these files not seem to match properly
so I can try to do We'll see if this works is, uh
I want to see if I can copy
the attributes from desktop dot Any?
Okay, uh, does it can't find that foul. I know what's in this directory.
Okay, there might be something
a little bit weird with this.
Okay, so that's not working, but that's that's fine. We can explore some of the other features.
One of the ones that one of the things I do want to see, though, is if I run Time Stone
with the file that I'm interested in
I can see that it was modified. I can see when it was accessed and created and so on. So it gives me some good information to work with.
If I'm not able, Thio, copy existing file. What I could do
either modify these parameters directly.
So that way I can kind of blend in this tools. Daddy, Actually, I could make it look like it was created
in 2014 or 2013 or something.
Ah, one. The other options is just to blank it out.
Now, if I review the changes that were made,
it just made the year 2106 used to be 2016. It was an accurate date before,
but now it's 2106 So if you're the investigator and you were looking at this, you'd be hard pressed to figure out exactly what happened. Although this is a little bit of a
a blunt method because it's it's changing, the file names her side of the file attributes in such a way that makes it obvious something strange is going on.
If you were to change this, to blend into a
existing time stamp from an older file
that would serve your purpose is better