Timeline Analysis: MACB Timestamps, Super Timelines & Timestomping
Individual artifacts from the last three chapters only become a story once they're placed in order. This chapter covers building and reading a forensic timeline, and catching attempts to falsify it.
Understanding MACB Timestamps
MACB is shorthand for the four timestamp types most filesystem and forensic tools track per file. Each letter answers a different question about what happened to a file and when.
| Timestamp | Meaning |
|---|---|
| Modified (M) | File content changed |
| Accessed (A) | File was read or opened |
| Changed (C) | File metadata changed, e.g. permissions |
| Born/Created (B) | File was created |
Building a Timeline
There are two ways to build a timeline, and most real investigations use both. Manual timeline building means pulling timestamps from individual artifacts one at a time, useful for verifying a specific claim.
A super timeline goes wider. It aggregates filesystem metadata, registry data, event logs, and other timestamped artifacts from an entire system into one sorted, searchable timeline. Plaso is the standard open-source engine for this: its log2timeline tool extracts timestamps from a wide range of artifact types into a single storage file, and psort filters, sorts, and exports that file into the timeline an examiner actually reads.
Timeline Analysis Technique
A raw timeline is noise until you know what to look for. Certain patterns of activity, called pivot points, tend to mark the moments worth investigating further.
| Pivot Point | What It Suggests |
|---|---|
| Burst of file creation activity | Bulk file drop, e.g. malware staging or archive extraction |
| Logon immediately followed by process execution | Interactive or remote access followed by an action |
| Cluster of registry key modifications around one timestamp | Configuration change, often persistence-related |
| Gap in event log coverage | Possible log clearing or tampering, explored more in chapter 8 |
Once you have a known-bad event, pivot outward in both directions in time. What happened in the minutes before it explains how the attacker got there; what happened after shows what they did with it.
Detecting Timestomping
Timestomping is deliberately altering a file's MACB timestamps to hide when it was really created or modified. It's a common step after dropping a malicious file, meant to make it blend in with legitimate system files.
The core detection technique compares two NTFS attributes. $STANDARD_INFORMATION timestamps are the ones commonly altered by timestomping tools. $FILE_NAME timestamps are a second, separate copy that's harder for common timestomping tools to reach. A disagreement between the two is a strong indicator of tampering.
Common Timeline Pitfalls
- Timezone normalization: artifacts from different sources can be logged in different timezones or UTC. Mixing them without converting to one common timezone produces a false sequence of events.
- Clock skew across systems: an investigation spanning multiple hosts needs each system's clock drift accounted for, or events that were actually simultaneous will look staggered.
- Over-reliance on a single timestamp source: one artifact type can be wrong, missing, or manipulated. Corroborate across artifact types, the same discipline covered in chapter 3's correlation section.
Key Takeaways
- MACB stands for Modified, Accessed, Changed, and Born/Created, four distinct answers to "what happened to this file and when."
- NTFS stores timestamps in two places: $STANDARD_INFORMATION (commonly shown by tools) and $FILE_NAME (a second, less-tampered copy).
- A super timeline aggregates filesystem, registry, and event log timestamps system-wide into one sorted, searchable view.
- Pivot points like file creation bursts, logon-to-execution sequences, and registry modification clusters mark moments worth investigating.
- Timestomping is detected by comparing $STANDARD_INFORMATION against $FILE_NAME; a disagreement between the two is a strong indicator of tampering.
- Timezone normalization and clock skew correction are required before events from multiple sources can be trusted in sequence.
Knowledge Check
Click an answer to reveal the explanation.
In MACB, what does the "C" represent?
Which comparison is the core technique for detecting timestomping on NTFS?
Why is timezone normalization critical before analyzing a multi-source timeline?