← Main site

ZEKASTRA / FORENSIC

Inspect the facts. Document the limits.

Professional-oriented learning resources: timestamps, file hashes, reproducible steps and synthetic investigations.

The exercises are not forensic validation or chain-of-custody software. Use synthetic or authorized non-sensitive samples; never upload real investigation material to the public website.

01 / Learn

Timestamp interpretation

NTFS commonly records file times as FILETIME values (100-nanosecond units since 1601-01-01 UTC). FAT timestamps are local-time-oriented and have varying granularity; FAT last-write times are typically recorded in two-second increments. Unix timestamps count seconds or milliseconds since 1970-01-01 UTC. A time value alone does not prove who performed an action.

02 / Try

Windows FILETIME → UTC

Enter an unsigned integer in 100 ns ticks, without thousands separators. The calculation uses exact integer arithmetic and displays UTC plus the remaining 100 ns fraction.

Compare NTFS, FAT32 and Unix time bases →

Open Unix time and local file hash tools →

03 / Produce

Document a finding

Keep source, method, unit, reference time, calculated output and limitations distinct. The local Content Studio produces editable drafts for review, not expert conclusions.

04 / Play

Missing USB: chronology exercise

Examine four fictional events with explicit UTC offsets, reconstruct the correct order and write the limits of your interpretation.

Start synthetic case