One of the most important parts of digital forensics is working out when things happened. When did a file get last accessed or modified? When did a user access this website? What was happened yesterday at 4.30PM? This would be very easy if the entire world was based in UTC, or at least all operating systems and log files stored time in UTC in the same format. Instead, we have various mixtures of UTC and local time, stored in Windows time format (100 nanosecond intervals since Jan 1st 1601) or Unix epoch format (seconds since Jan 1st 1970), a plain string format or however each programming language decides to encode time. This is especially important when doing forensics for global companies where the investigation can be carried out on several computers spanning different timezones, and the investigator is in a different timezone too. Establishing a common timezone is imperative, so not to get lost with local times and correlating evidence. Even on the same machine this is difficult - the Windows registry is in UTC, but setupapi.log and other important log file are in localtime.
chocolate coffee facts iPod touch beach Derren Brown qualitative demographics internet statistics readability Number One proxy logs Microsoft Word bibliography thesis criminology encryption web history Barranco camp Data Protection Act 30 Seconds to Mars hacking Python search terms Strathclyde abandoned buildings laptop Asda censorship tea Registry risotto security Firefox crime scene The Balmoral unicode Sainsbury's JavaScript fabrics crime moving flat gardening Barcelona play Christmas exams Pixel Megalosaurus treats Geocities captcha arts fair promotion paintings asparagus SANS sock puppets counting conference