The Forensic ToolKit 1.1 from NT OBJECTives, Inc. Copyright(c)1998 NT OBJECTives, Inc. All Rights Reserved AFind - File access time finder SFind - Hidden data streams finder HFind - Hidden file finder FileStat - Dumps file stats in a readable format Hunt - List available NetBIOS info and true admin name This toolkit contains several tools that can help you examine the files on a disk drive for unauthorized activity. We built these tools to help us do our job, we hope they can help you as well. WE PRESENT THESE TOOLS AS IS. NO WARRENTY EXPRESSED OR IMPLIED. AFind is a tool that lists files by their last access time without CONTAMINATING the dates the way that right-clicking on file in Explorer and looking at the properties dialog will. AFind allows you to search for access times between certain time frames, Coordinating this with logon info provided from ntlast, you can to begin determine user activity even if file logging has not been enabled. HFind scans the disk for hidden files. It will find files that have either the hidden attribute set, or NT's unique and painful way of hiding things by using the directory/system attribute combination. This is the method that IE uses to hide data. HFind lists the last access times. SFind scans the disk for hidden data streams and lists the last access times. FileStat is a quick dump of all file and security attributes. It works on only one file at a time but is thorough. Hunt is a quick way to see if a server reveals too much info via NULL sessions. COMMAND PROMPT MUST HAVE A MINIMUM WIDTH OF 80 CHARACTERS Command line switches afind [dir] /f [filename] /ns no sub-directories /smhd [amount] seconds,minutes,hours,days /a [date-time] actual date-time hfind [dir] /hd=find dir/system attribs /ns=no subs sfind [dir] /ns=no subs filestat [filename] hunt [\\servername] Hope these prove useful to you Cheers, JD Glaser NT OBJECTives, Inc. jdglaser@ntobjectives.com See www.ntobjectives.com for updates.