Digital Forensic Data Recovery & Analysis

NetAnalysis Date and Time Fields

No Comments »

Some of you will have noticed that from NetAnalysis v1.50 there have been numerous new date and time columns added.  These new timestamps were identified during months of research and development and are now included with the latest release.  Figure 1 shows some of the new fields from Internet Explorer.  This article will look at each of the new columns and explain what they mean.

 

NetAnalysis_New_Timestamp_Fields

Figure 1

  

Last Visited [UTC]

This column should be self explanatory.  It is the timestamp which reflects the last known recorded visit to a webpage (or object) in Coordinated Universal Time (UTC).  Normally, this timestamp is extracted directly from the source record and not changed in any way by the time zone information set in NetAnalysis.  With the exception of Internet Explorer Weekly INDEX.DAT records, all other records have their timestamps saved as UTC values.  Weekly records are stored as local times and therefore have to be converted to UTC to fill this column.

  

Last Visited [Local]

This column contains the timestamp which reflects the last known recorded visit to a webpage (or object) in Local time.  This timestamp is calculated by using the data from the Last Visited [UTC] column and converting it to Local time using the time zone information set in NetAnalysis prior to extraction (with the exception of Daily INDEX.DAT records which is already stored in Local time).

  

Date Expiration [UTC]

This column contains a timestamp (in UTC) which reflects the date and time when the object or record is no longer regarded as valid by the browser.  For example, in History records, you will see that the expiration time is set according to the amount of days the browser is set to keep history records, whilst the cache expiration time can be set by the web developer and is delivered to the browser during the HTTP response.  This column reflects the ExpireTime field in the INTERNET_CACHE_ENTRY_INFO Structure. 

  

Date Last Modified [UTC]

This column contains a timestamp (in UTC) which reflects the date and time the webpage (or object) was last modified (last written).  This information is passed back to the browser as part of the HTTP response.  Since origin servers do not always provide explicit expiration times, HTTP caches typically assign heuristic expiration times, employing algorithms that use other header values (such as the Last-Modified time) to estimate a plausible expiration time.

 

  

Date Index Created [UTC]

This column contains a timestamp (in UTC) which reflects the date and time the Weekly INDEX.DAT file from Internet Explorer was created.

  

Date Last Synch [UTC

This column contains a timestamp (in UTC) which reflects the last date and time at which an object was checked for freshness with the origin server.  LastSyncTime is initially set as the time at which an object is added to the cache, and is updated every time the browser verifies freshness of the object with the server.

 

Date First Visited [UTC]

This column contains a timestamp (in UTC) which is available during the extracting of Netscape and Firefox v1-2 History.  It reflects the first date and time at which a web page (or object) was visited.

 

Date Added [UTC]

This column contains a timestamp (in UTC) which is available during the extracting of Netscape, Firefox and Mozilla bookmark files.  It reflects the date and time at which an entry was added to the bookmark file.

 

References

·         KB80013 Internet Explorer INTERNET_CACHE_ENTRY_INFO Structure

·         KB80072 Microsoft Internet Explorer Daily INDEX.DAT Entries

·         KB80073 Microsoft Internet Explorer Weekly INDEX.DAT Entries

·         KB80004 Identification of Suspect Computer Time Zone

·         Caching in HTTP

10% Discount for SANS European Digital Forensics & Incident Response Summit

No Comments »

SANS 2010 European Digital Forensics & Incident Response Summit

Join your peers in London, September 8 – 9, 2010 for the first SANS European Digital Forensics and Incident Response Summit, and hear forensics experts help you get the most out of your Forensics and Incident Response strategies operations.

In the commercial sector, TJ Maxx, Hannaford, and TD Ameritrade are victims of large-scale data breaches and intrusions.  From these attacks, personal or account information of more than 100 million individuals has been compromised.

In the government sector, cyber attacks on government agencies and contractors, originating from China, have proved difficult to suppress.  In both situations, incident response and mitigation, class action lawsuits, and fines place remediation costs in the billions of dollars.

Why is this event special?

The speakers.  There is a lot of talent in the EU which is often not sufficiently exposed because they don’t have the chance to travel all the way to the US.  Similarly the vast majority of the Forensics Community cannot afford to travel there.  With this Summit we want to create an opportunity for the EU forensic community to meet the local experts and learn from their invaluable knowledge and experience.

You, the Community.  We want to create an opportunity to share experiences with your colleagues and with others from Law Enforcement, Military Agencies, Corporations, Financial Companies, Telecommunication Companies, etc.  You can exchange ideas on how to approach and solve some of the most excruciating problems today: short budgets, transnational investigations, legislation, malware, fraud, etc.

Localisation.  Even when there are similar problems or solutions, tools and techniques are used all around the world, in the SANS European Incident Response and Forensics Summit we want to define EU-specific problems and together find solutions to them.

We don’t want to forget that the EU receives multiple visitors from all over Africa, Middle East and Asia.  We also want to welcome them to this Summit, as they all have similar problems to the ones we have.

We want the SANS Forensics Summit to be your favourite event of the year, the forum in which the top experts in the EU and nearby regions, the Vendors and the Community will have the chance to meet and share knowledge, experience and solutions, and we will work hard to make that happen.

We’ve teamed up with SANS to bring Digital Detective Customers and Forum Members the chance to attend these events and receive a 10% Discount.

Register Here for a 10% Discount

use the Digital Detective discount code: DFIRSTNDD10

Please join us for this innovative meeting on Forensics & Incident Response.  There is simply no other place where you can learn – from those who have done it – what works to protect your organisation’s crown jewels – its data.

Google Analytics integration offered by Wordpress Google Analytics Plugin