ZEKASTRA / FORENSIC
Inspect the facts. Document the limits.
Professional-oriented learning resources: timestamps, file hashes, reproducible steps and synthetic investigations.
The exercises are not forensic validation or chain-of-custody software. Use synthetic or authorized non-sensitive samples; never upload real investigation material to the public website.
01 / Learn
Timestamp interpretation
NTFS commonly records file times as FILETIME values (100-nanosecond units since 1601-01-01 UTC). FAT timestamps are local-time-oriented and have varying granularity; FAT last-write times are typically recorded in two-second increments. Unix timestamps count seconds or milliseconds since 1970-01-01 UTC. A time value alone does not prove who performed an action.
02 / Try
Windows FILETIME → UTC
Enter an unsigned integer in 100 ns ticks, without thousands separators. The calculation uses exact integer arithmetic and displays UTC plus the remaining 100 ns fraction.
03 / Produce
Document a finding
Keep source, method, unit, reference time, calculated output and limitations distinct. The local Content Studio produces editable drafts for review, not expert conclusions.
04 / Play
Missing USB: chronology exercise
Examine four fictional events with explicit UTC offsets, reconstruct the correct order and write the limits of your interpretation.
Start synthetic case