<?xml version="1.0"?>
<?xml-stylesheet type="text/css" href="http://www.forensicswiki.org/w/skins/common/feed.css?303"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>http://www.forensicswiki.org/w/index.php?title=Aftertime&amp;feed=atom&amp;action=history</id>
		<title>Aftertime - Revision history</title>
		<link rel="self" type="application/atom+xml" href="http://www.forensicswiki.org/w/index.php?title=Aftertime&amp;feed=atom&amp;action=history"/>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/w/index.php?title=Aftertime&amp;action=history"/>
		<updated>2013-05-19T11:27:00Z</updated>
		<subtitle>Revision history for this page on the wiki</subtitle>
		<generator>MediaWiki 1.20.3</generator>

	<entry>
		<id>http://www.forensicswiki.org/w/index.php?title=Aftertime&amp;diff=10272&amp;oldid=prev</id>
		<title>Vanbaar: /* Screenshots */</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/w/index.php?title=Aftertime&amp;diff=10272&amp;oldid=prev"/>
				<updated>2010-04-16T06:03:10Z</updated>
		
		<summary type="html">&lt;p&gt;‎&lt;span dir=&quot;auto&quot;&gt;&lt;span class=&quot;autocomment&quot;&gt;Screenshots&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;table class='diff diff-contentalign-left'&gt;
				&lt;col class='diff-marker' /&gt;
				&lt;col class='diff-content' /&gt;
				&lt;col class='diff-marker' /&gt;
				&lt;col class='diff-content' /&gt;
			&lt;tr style='vertical-align: top;'&gt;
			&lt;td colspan='2' style=&quot;background-color: white; color:black;&quot;&gt;← Older revision&lt;/td&gt;
			&lt;td colspan='2' style=&quot;background-color: white; color:black;&quot;&gt;Revision as of 06:03, 16 April 2010&lt;/td&gt;
			&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 98:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 98:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;==Screenshots==&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;==Screenshots==&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;background: #ffa; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;Screenshots can be found on the &lt;/del&gt;[&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;http&lt;/del&gt;:&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;//www&lt;/del&gt;.&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;holmes.nl/NFIlabs/&lt;/del&gt;Aftertime&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;/screenshots.html screenshots&lt;/del&gt;] &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;section of the &lt;/del&gt;[&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;http&lt;/del&gt;:&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;//www&lt;/del&gt;.&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;holmes.nl/NFIlabs/Aftertime &lt;/del&gt;Aftertime]&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;-website&lt;/del&gt;.&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;[&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;[File&lt;/ins&gt;:&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;Aftertime1_large&lt;/ins&gt;.&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;png|200px|thumbs|&lt;/ins&gt;Aftertime &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;screenshot&lt;/ins&gt;]&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;]&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;[&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;[File&lt;/ins&gt;:&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;Aftertime2_large&lt;/ins&gt;.&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;png|200px|thumbs|&lt;/ins&gt;Aftertime &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;screenshot&lt;/ins&gt;]&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;]&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;[[File:Aftertime3_large&lt;/ins&gt;.&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;png|200px|thumbs|Aftertime screenshot]]&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;==Links==&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;==Links==&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;; [http://www.holmes.nl/NFIlabs/Aftertime/index.html Aftertime website]&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;; [http://www.holmes.nl/NFIlabs/Aftertime/index.html Aftertime website]&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Vanbaar</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/w/index.php?title=Aftertime&amp;diff=10271&amp;oldid=prev</id>
		<title>Vanbaar: Created page with '{{Infobox_Software |   name = Aftertime |   maintainer = NFI |   os = Java |   genre = {{Analysis}}  |   license = proprietary |   website = http://www.holmes.nl/NFIlabs/Aftertim…'</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/w/index.php?title=Aftertime&amp;diff=10271&amp;oldid=prev"/>
				<updated>2010-04-16T05:59:10Z</updated>
		
		<summary type="html">&lt;p&gt;Created page with &amp;#039;{{Infobox_Software |   name = Aftertime |   maintainer = NFI |   os = Java |   genre = {{Analysis}}  |   license = proprietary |   website = http://www.holmes.nl/NFIlabs/Aftertim…&amp;#039;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;{{Infobox_Software |&lt;br /&gt;
  name = Aftertime |&lt;br /&gt;
  maintainer = NFI |&lt;br /&gt;
  os = Java |&lt;br /&gt;
  genre = {{Analysis}}  |&lt;br /&gt;
  license = proprietary |&lt;br /&gt;
  website = http://www.holmes.nl/NFIlabs/Aftertime |&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
==Aftertime==&lt;br /&gt;
&lt;br /&gt;
'''Aftertime''' is a Java software application that can be used to create [[Timeline_Analysis_Bibliography|time lines]] for forensic investigators. Aftertime is based on [[Snorkel]] to provide access to a large number of image file formats, partition schemes, file systems and file formats. Aftertime not only uses time information contained in the file system but also extracts time information from file contents, e.g. event logs, internet history, e-mail and more. The winners of the [[DFRWS]] [http://www.dfrws.org/2009/challenge/index.shtml 2009 Forensic Challenge] used Aftertime to create the timeline. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Features==&lt;br /&gt;
&lt;br /&gt;
With Aftertime it is possible to set the time zone per project, per image, per scanner or change the time zone displayed. The file types supported are summarized below. &lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|E-mail&lt;br /&gt;
|[[MBox|Mbox]]&lt;br /&gt;
|-&lt;br /&gt;
|Files&lt;br /&gt;
|[[LNK|Shortcuts]]&lt;br /&gt;
|-&lt;br /&gt;
| &lt;br /&gt;
|[[MAC_times|MAC-times]]&lt;br /&gt;
|-&lt;br /&gt;
|Internet history&lt;br /&gt;
|[[Internet_Explorer|Internet Explorer cookies]]&lt;br /&gt;
|-&lt;br /&gt;
| &lt;br /&gt;
|[[Internet_Explorer_History_File_Format|Internet Explorer history]]&lt;br /&gt;
|-&lt;br /&gt;
| &lt;br /&gt;
|[[Apple_Safari_History_File_Format|Safari history]]&lt;br /&gt;
|-&lt;br /&gt;
| &lt;br /&gt;
|[[Safari|Safari cookies]]&lt;br /&gt;
|-&lt;br /&gt;
| &lt;br /&gt;
|[[Opera|Opera cookies]]&lt;br /&gt;
|-&lt;br /&gt;
| &lt;br /&gt;
|[[Firefox|Mozilla/Firefox cookies]]&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|[[Mozilla_Firefox_History_File_Format|Mozilla]]/[[Mozilla_Firefox_3_History_File_Format|Firefox]] history&lt;br /&gt;
|-&lt;br /&gt;
|Logs&lt;br /&gt;
|[[MSN]]&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|WTMP&lt;br /&gt;
|-&lt;br /&gt;
| &lt;br /&gt;
|Console kit&lt;br /&gt;
|-&lt;br /&gt;
| &lt;br /&gt;
|Zone alarm&lt;br /&gt;
|-&lt;br /&gt;
| &lt;br /&gt;
|Gator&lt;br /&gt;
|-&lt;br /&gt;
| &lt;br /&gt;
|setupapi.log&lt;br /&gt;
|-&lt;br /&gt;
| &lt;br /&gt;
|WBEM&lt;br /&gt;
|-&lt;br /&gt;
|Multimedia&lt;br /&gt;
|[[Exif]]&lt;br /&gt;
|-&lt;br /&gt;
|Operating System&lt;br /&gt;
|[[EVT|Windows Event log]]&lt;br /&gt;
|-&lt;br /&gt;
| &lt;br /&gt;
|[[Prefetch|Windows Prefetch]]&lt;br /&gt;
|-&lt;br /&gt;
| &lt;br /&gt;
|Linux / Macintosh logs&lt;br /&gt;
|-&lt;br /&gt;
| &lt;br /&gt;
|[[Windows_Registry|Windows Registry]]&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|Windows Shadow-files&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Examples of use==&lt;br /&gt;
Aftertime is used in a wide variety of cases:&lt;br /&gt;
* Was a person using this system at a specific time (alibi)?&lt;br /&gt;
* Are there traces of malicious activity at a given time?&lt;br /&gt;
* Are there any traces of other activity while this file was downloaded?&lt;br /&gt;
* When was this letter written?&lt;br /&gt;
Aftertime has two different views on the data. The first display is a graphical view, where events are presented in a histogram. It is possible to display the events in a logarithmic scale to not overlook events that are only present a limited number of times. The second display is a list of events with the details of each event presented by highlighting the event.&lt;br /&gt;
&lt;br /&gt;
==Screenshots==&lt;br /&gt;
Screenshots can be found on the [http://www.holmes.nl/NFIlabs/Aftertime/screenshots.html screenshots] section of the [http://www.holmes.nl/NFIlabs/Aftertime Aftertime]-website.&lt;br /&gt;
&lt;br /&gt;
==Links==&lt;br /&gt;
; [http://www.holmes.nl/NFIlabs/Aftertime/index.html Aftertime website]&lt;/div&gt;</summary>
		<author><name>Vanbaar</name></author>	</entry>

	</feed>