The workstation that went back to 2019

A finance workstation, a July morning, and a binary claiming to be seven years old.

Somebody in finance reported their machine running hot. The first responder pulled a triage collection, ran it through the usual parsers, and handed you the output. There is a binary in a temp directory that says it was created in 2019, an archive nobody can find, and a logon nobody has explained.

query consoleloading evidence…

Start with a question. Each one runs a query and shows you the query it ran, so the second tab stops being a blank box.

Or open a table and read it.

questions 0 of 5 answered

Get the answer into the first cell of a result, then check it. Clicking a question above counts: it runs a real query, and checking grades what the query returned rather than a guess typed into a box.

  1. One file on this host has been timestomped. Return its path.

  2. The timestomper zeroed something it should not have. Return the si_created value that gives it away.

  3. An archive was staged and then deleted, so it is absent from the MFT as a live file. Return its path from the journal.

  4. Which account logged on over RDP? Return the account name.

  5. How many times did the planted binary run before it was deleted? Return the number.

what this one teaches

Comparing the two NTFS timestamp sets, and finding a deleted file in the change journal.

The reasoning behind each artifact is in the artifact reference, and the collection order is in the evidence-gap checker.

Next case: Four hours before the ransom note