CHAPTER 05 30 MIN READ INTERMEDIATE

Timeline Analysis: MACB Timestamps, Super Timelines & Timestomping

Individual artifacts from the last three chapters only become a story once they're placed in order. This chapter covers building and reading a forensic timeline, and catching attempts to falsify it.

MACB timestampssuper timelinetimestompingtimeline pivoting

Understanding MACB Timestamps

MACB is shorthand for the four timestamp types most filesystem and forensic tools track per file. Each letter answers a different question about what happened to a file and when.

TimestampMeaning
Modified (M)File content changed
Accessed (A)File was read or opened
Changed (C)File metadata changed, e.g. permissions
Born/Created (B)File was created
Note: On NTFS, these four values actually exist in two separate places: $STANDARD_INFORMATION, which is what most tools show by default, and $FILE_NAME, a second, often-overlooked copy. The two can be made to disagree, which matters when we get to timestomping later in this chapter.

Building a Timeline

There are two ways to build a timeline, and most real investigations use both. Manual timeline building means pulling timestamps from individual artifacts one at a time, useful for verifying a specific claim.

A super timeline goes wider. It aggregates filesystem metadata, registry data, event logs, and other timestamped artifacts from an entire system into one sorted, searchable timeline. Plaso is the standard open-source engine for this: its log2timeline tool extracts timestamps from a wide range of artifact types into a single storage file, and psort filters, sorts, and exports that file into the timeline an examiner actually reads.

Note: A super timeline trades precision for coverage. It surfaces far more events than a manual pull, but that volume needs filtering and pivoting to be useful, not just scrolling.

Timeline Analysis Technique

A raw timeline is noise until you know what to look for. Certain patterns of activity, called pivot points, tend to mark the moments worth investigating further.

Pivot PointWhat It Suggests
Burst of file creation activityBulk file drop, e.g. malware staging or archive extraction
Logon immediately followed by process executionInteractive or remote access followed by an action
Cluster of registry key modifications around one timestampConfiguration change, often persistence-related
Gap in event log coveragePossible log clearing or tampering, explored more in chapter 8

Once you have a known-bad event, pivot outward in both directions in time. What happened in the minutes before it explains how the attacker got there; what happened after shows what they did with it.

Detecting Timestomping

Timestomping is deliberately altering a file's MACB timestamps to hide when it was really created or modified. It's a common step after dropping a malicious file, meant to make it blend in with legitimate system files.

The core detection technique compares two NTFS attributes. $STANDARD_INFORMATION timestamps are the ones commonly altered by timestomping tools. $FILE_NAME timestamps are a second, separate copy that's harder for common timestomping tools to reach. A disagreement between the two is a strong indicator of tampering.

Example: A file's $STANDARD_INFORMATION shows a date from years ago, while its $FILE_NAME shows today. That's backwards from what legitimate copying or moving normally produces, and it's a red flag worth pulling on.

Common Timeline Pitfalls

  • Timezone normalization: artifacts from different sources can be logged in different timezones or UTC. Mixing them without converting to one common timezone produces a false sequence of events.
  • Clock skew across systems: an investigation spanning multiple hosts needs each system's clock drift accounted for, or events that were actually simultaneous will look staggered.
  • Over-reliance on a single timestamp source: one artifact type can be wrong, missing, or manipulated. Corroborate across artifact types, the same discipline covered in chapter 3's correlation section.
1Normalize timezonesConvert every source to one common timezone before comparing
→
2Corroborate across sourcesConfirm key events against more than one artifact type
→
3Pivot from known eventsWork outward in both directions from a confirmed pivot point
→
4Document assumptionsRecord timezone conversions and skew corrections applied

Key Takeaways

  • MACB stands for Modified, Accessed, Changed, and Born/Created, four distinct answers to "what happened to this file and when."
  • NTFS stores timestamps in two places: $STANDARD_INFORMATION (commonly shown by tools) and $FILE_NAME (a second, less-tampered copy).
  • A super timeline aggregates filesystem, registry, and event log timestamps system-wide into one sorted, searchable view.
  • Pivot points like file creation bursts, logon-to-execution sequences, and registry modification clusters mark moments worth investigating.
  • Timestomping is detected by comparing $STANDARD_INFORMATION against $FILE_NAME; a disagreement between the two is a strong indicator of tampering.
  • Timezone normalization and clock skew correction are required before events from multiple sources can be trusted in sequence.

Knowledge Check

Click an answer to reveal the explanation.

In MACB, what does the "C" represent?

Correct answer: B. Changed refers to metadata changes, such as permissions, not content changes (that's Modified).

Which comparison is the core technique for detecting timestomping on NTFS?

Correct answer: B. $STANDARD_INFORMATION is what most timestomping tools alter; $FILE_NAME is a second copy that's harder to reach. A disagreement between them is a strong tampering indicator.

Why is timezone normalization critical before analyzing a multi-source timeline?

Correct answer: C. Without converting every source to one common timezone, event ordering across artifacts can appear wrong even when nothing was tampered with.