Expose Evidence of Timestomping with the NTFS Timestamp Mismatch Artifact
The goal of timestomping is to edit the timestamps being displayed and reported to the end user and incident responders in an attempt to make it seem as though the file doesn’t fall into the timeline of other detected malicious activity.