Hi
One of my friends Sandy asked me about the possibility of completely change MACE timestamps. As everybody knows that some tools could change MAC timestamps only. I told her, a tool whose name is "Timestomp" could the change MACE timestamps,including Entry Modified time. She was very surprise and ask me about use "Timestomp". I'll show you as below:
1. A File-test.txt. Look at its MAC timestamps "10/29/2013 09:44:35".
2. Use Timestomp to show MACE timestamps.
3. Now I use the Timestomp to change MACE timestamps to earlier time such as "10/08/2005 14:34:56". You could see the MACE timestamps change as exaclty what I want.
4.If you is not sure MACE don't, I use other tool to verify the MACE timestamp of this file Test.txt again. It works! All timestamps become "10/08/2005 14:34:56".
5. My Friend She wonder if suspect use Timestomp to change MACE timestamps, what could I figure it out? Fortunately, there is both kinds of timestamps in the MFT. They is standard info and Filename info. I dump an MFT to the CSV and you could see them clearly. Even Timestomp could change MACE timestamps, it could only change Sandard info attributes, not including Filename info att Ributes. So we could take a look at the MFT dump results and see if there are any abnormal timestamps between those both timestamp attrib Utes.
Completely Change MACE timestamps?