FTimes
From Forensics Wiki
| FTimes | |
|---|---|
| Maintainer: | Klayton Monroe |
| OS: | Template:Multiplatform |
| Genre: | Evidence collection |
| License: | BSD |
| Website: | ftimes.sf.net |
FTimes, short for File Topography and Integrity Monitoring on an Enterprise Scale is a system baselining and evidence collection tool designed for incident response, evidence collection (alternate data streams, hidden files), content integrity monitoring, intrusion analysis and computer forensics.
Limitations
FTimes does not collect all possible attributes on every supported platform.
External Links
- The FTimes Project Homepage
- Building FTimes on Windows using Visual Studio
- DFRWS 2006 File Carving Challenge - using FTimes