@port139 Blog

基本的にはデジタル・フォレンジックの技術について取り扱っていますが、記載内容には高確率で誤りが含まれる可能性があります。

NTFS last access time and 1 hour (2)

Note:I translated Japanese into English using Google Translate.
Thank you, Google.  

Summary:

  1. I used FTK Imager and Autopsy as a tool to check Last Access Time on NTFS volume. However, adding Local Drive did not produce the expected results.
    (I lost a lot of time with this repetition.)
  2. Using "PHYSICALDRIVE", expected results were obtained.
  3. I recommend you to check with PHYSICALDRIVE in the Last Access Time test.

---

I continue to test last access time on the Win 10 1803 environment.

Please note that it is not a sufficient verification method.

DisableLastAccess = 2 (System Managed, Disabled) ⇒ Last Access Time updates are enabled.
The test volume F: is NTFS and the size is 149 GB.

Check the latest time stamp with the fsutil command.

f:id:hideakii:20181211194703p:plain

Display properties of Dragonfly.jpg in Explorer. Last Access Time has been updated by this operation.(Close the property and close Explorer.)

Check the latest time stamp with the fsutil command.

f:id:hideakii:20181211195748p:plain

Refer to Physicaldrive 2 and check the time stamp. An old timestamp on the disk was displayed.

f:id:hideakii:20181211195836p:plain

Add Local Drive F: and check the time stamp. Interestingly, adding Local Drive F: will update the latest timestamp. (This also happens with Autopsy.)

f:id:hideakii:20181211200132p:plain

When accessing the logical drive, flash the latest information to the disk?

I recommend you to check with PHYSICALDRIVE in the Last Access Time test.
Because I was referring to F: in the test, I lost a lot of time.

 

Verification environment: Windows 10 1803

Reference URL:

 

 

f:id:hideakii:20181211184548j:plain