Collect NTFS forensic information with osquery
Common Information
Type Value
UUID d65a6ce4-6a0b-4159-91b9-9346cc51d828
Fingerprint 998d4a1656e44cbe
Analysis status DONE
Considered CTI value 0
Text language
Published May 28, 2018, 12:06 p.m.
Added to db Jan. 18, 2023, 9 p.m.
Last updated Nov. 17, 2024, 6:55 p.m.
Headline Trail of Bits Blog
Title Collect NTFS forensic information with osquery
Detected Hints/Tags/Attributes 18/1/3
Attributes
Details Type #Events CTI Value
Details File 312
calc.exe
Details File 2
osqueryi.exe
Details File 2
ext.exe