Is it possible that a usb drive manufactured 3 months ago can have data copied to it that shows the file last modified date before manufacturing date? [on hold]

I have some data that needs to be handed to a friend. I don’t want to give the original drive (drive-1), so I plan to purchase a drive (drive-copy) and copy data to it. The data copied will still show last modified date for f… Continue reading Is it possible that a usb drive manufactured 3 months ago can have data copied to it that shows the file last modified date before manufacturing date? [on hold]

If a file on USB drive shows a certain "date modified" time in the windows explorer, can the correct added date/time be checked for the file?

If someone copied files from a drive-1 to usb-drive-2, then it seems the directories and files get the original modified time from drive-1 in some cases and in some cases not.

Can it be checked if the file/directory was act… Continue reading If a file on USB drive shows a certain "date modified" time in the windows explorer, can the correct added date/time be checked for the file?

Can someone tell by looking at USB drive whether those files have been copied to elsewhere from USB or if some files on USB were deleted?

I was wondering if one can find if files were copied from the USB drive to a PC or something, and also if any and which files were recently deleted from the USB.

Continue reading Can someone tell by looking at USB drive whether those files have been copied to elsewhere from USB or if some files on USB were deleted?

How to capture not only the mtime but also the ctime when making forensic copies of files?

Context

I’m investigating a compromised Linux box where I found files with malicious code. The file system is too big to just make a copy of the whole block device and so far I’m only interested in the files of a not so big sub-directory…. Continue reading How to capture not only the mtime but also the ctime when making forensic copies of files?