Which TWO of the following MFT attributes are most relevant for detecting timestomping activity?
Trap 1: $DATA and $BITMAP
The $DATA attribute contains the actual file content, while the $BITMAP tracks cluster allocation. Neither of these attributes stores timestamps used for forensic timeline analysis, so relying on them for detecting timestomping would be ineffective as they do not provide the metadata fields necessary for verifying file system time history.
Trap 2: $ATTRIBUTE_LIST and $EA
$ATTRIBUTE_LIST is used when a file has too many attributes for a single MFT record, and $EA stores extended attributes. These are structural components of the MFT and do not serve as the primary source for the standard MACE (Modified, Accessed, Created, Entry Modified) timestamps used in forensic investigations.
Trap 3: $STANDARD_INFORMATION and $DATA
While $STANDARD_INFORMATION contains timestamps, the $DATA attribute is reserved for the file's primary stream content. Since $DATA lacks timestamps, this combination fails to provide the necessary metadata comparison required to detect timestomping, as you would have no reference point to validate the accuracy of the $STANDARD_INFORMATION timestamp values.
- A
$STANDARD_INFORMATION and $FILE_NAME
These two attributes both contain modification, access, and creation timestamps. Discrepancies between them are a hallmark indicator of timestomping, as automated tools often only touch the $STANDARD_INFORMATION attribute, leaving the $FILE_NAME attribute with the original, accurate forensic timeline information that is much harder for user-level tools to modify.
- B
$DATA and $BITMAP
Why it fails: The $DATA attribute contains the actual file content, while the $BITMAP tracks cluster allocation. Neither of these attributes stores timestamps used for forensic timeline analysis, so relying on them for detecting timestomping would be ineffective as they do not provide the metadata fields necessary for verifying file system time history.
- C
$ATTRIBUTE_LIST and $EA
Why it fails: $ATTRIBUTE_LIST is used when a file has too many attributes for a single MFT record, and $EA stores extended attributes. These are structural components of the MFT and do not serve as the primary source for the standard MACE (Modified, Accessed, Created, Entry Modified) timestamps used in forensic investigations.
- D
$STANDARD_INFORMATION and $DATA
Why it fails: While $STANDARD_INFORMATION contains timestamps, the $DATA attribute is reserved for the file's primary stream content. Since $DATA lacks timestamps, this combination fails to provide the necessary metadata comparison required to detect timestomping, as you would have no reference point to validate the accuracy of the $STANDARD_INFORMATION timestamp values.
- E
$FILE_NAME and $VOLUME_INFORMATION
Why it fails: $FILE_NAME contains timestamps, but $VOLUME_INFORMATION is a metadata file describing the volume itself, not individual files. This pair does not provide the required contrast between user-accessible metadata and system-level metadata, making it impossible to effectively identify malicious timestamp tampering or unauthorized modifications to file metadata values.