ZEKASTRA / Fictional case study 02
Night Shift: when midnight misleads.
A fictional notification, workstation notes, gateway entry and archive job use two clock representations. Can you order five events without confusing local dates and UTC?
SYNTHETIC TRAINING CASE — no real people, devices, network traffic, evidence or case numbers. All UTC offsets are deliberately explicit. A timestamp alone cannot establish who acted, whether a record is authentic or whether clocks were synchronized.
01 / Inspect sources
Download original fictional files
All five timestamps indicate an explicit Z or +03:00 UTC offset. One local workstation record has the following calendar date, but the UTC day is still October 9, 2026. Keep timestamps and source descriptions together when comparing.
02 / Reconstruct
Choose every event, earliest UTC first
Don't trust the hour or date shown without its offset. Select each record once, then check the complete sequence.
03 / Document findings
Produce a reproducible training note
A correct sequence unlocks an editable UTC chronology. Distinguish the order in this invented dataset from actual events or evidence authenticity.
Continue in the forensic training report workshop (copy and paste) →
04 / Discuss and verify
What does an ordered timestamp prove?
Nothing about a real individual, an actual device operation or the accuracy of clocks. A source log, acquisition context, synchronization record and alternative explanations would need independent verification.
For educators: reveal facilitator answer key (spoiler)
The answer key explicitly gives all five UTC values, the intended order and the limitations of any interpretation.
Download bilingual solution key (TXT)