@port139 Blog

基本的にはデジタル・フォレンジックの技術について取り扱っていますが、記載内容には高確率で誤りが含まれる可能性があります。

File System Tunneling and E:\

Note:I translated Japanese into English using Google Translate.
Thank you, Google. 

iria_piyo has published some interesting verifications on File System Tunneling in the blog. I read those blogs and I wanted to see how the USN Journal was recorded.

(2013 article in the reference URL, Keydet89 has already mentioned the USN journal.)

iria-piyo.hatenablog.com

Unfortunately I do not have an image of fried eggs (medamayaki.png) so I will use the otter image. 

Format E drive as NTFS and enable USN Journal.

E:\>fsutil usn createjournal e: m=1 a=1

f:id:hideakii:20181012201122j:plain

Copy the JPEG file to the E: Pictures folder using Windows Explorer.

f:id:hideakii:20181012182608j:plain

Check the file meta information with Autopsy.

f:id:hideakii:20181012185555j:plain

Delete the file and create the same file name. I should have recorded the time before deleting the file...

f:id:hideakii:20181012190026j:plain

Unlike expected results, Created timestamp was not restored.
...why?

f:id:hideakii:20181012190630j:plain

Copy the image file with a different name and test again.

f:id:hideakii:20181012191943j:plain

This time, the same file name is created by deleting the file and changing the file name.

f:id:hideakii:20181012192200j:plain

Created time stamp was not restored......why????

f:id:hideakii:20181012192741j:plain

Just to be sure, I check the registry, but there is no value of MaximumTunnelEntries.
By the way, why is NtfsDisableLastAccessUpdate value 80000002? (DisableLastAccess = 2 (System Managed, Disabled))

f:id:hideakii:20181012193504j:plain

I will test the same operation on the C: drive.
As before, I copied the otter image to c:\Pictures folder.

f:id:hideakii:20181012195235j:plain

f:id:hideakii:20181012195634j:plain

Created timestamp has been restored.

f:id:hideakii:20181012195958j:plain

 Muuuuuu...Why is the Created time stamp not restored on E: drive?

 

<FAT32>

I formatted E: drive with FAT32, and performed the same test, it was the result below.

f:id:hideakii:20181012204329j:plain

f:id:hideakii:20181012204910j:plain

f:id:hideakii:20181012205330j:plain

f:id:hideakii:20181012205339j:plain

On FAT32, Created time stamp is restored.

 

 

Verification environment: Windows 10 1083

Reference URL:

www.afodblog.com

 

 

f:id:hideakii:20181012180753j:plain