Daily Archives: January 14, 2018

SMB2 – File/Directory Metadata

Using SMB it is possible to retrieve data that is typically only expected when carrying out host based forensics.  The MACB (Modification, Access, Change and Birth) data is sent across regardless of if a file is accessed or not. With … Continue reading

Posted in Network Analytics, Network Forensics, SMB | Tagged , , | 1 Comment