Defense Evasion Tmstmp

Detect NTFS timestamp manipulation (MITRE T1070.006) by comparing $STANDARD_INFORMATION vs $FILE_NAME timestamps in the MFT. Uses analyzeMFT and Python to identify files with anomalous temporal patterns indicating anti-forensic timestomping activity.

undermybelt Updated

File contents

undermybelt/hermes-skills/tree/main/skills/red-teaming/anthropic-cybersecurity-skills/skills/defense-evasion-tmstmp commit 21cc368b0b

Frequently asked questions

npx skillmds@latest add undermybelt/defense-evasion-tmstmp