Difference between revisions of "Type UTMP"

From truxwiki.com
Jump to navigation Jump to search
Line 16: Line 16:
 
| No
 
| No
 
|-
 
|-
| File Meta Data
+
| Carve Meta Data
 
| Yes
 
| Yes
 
|-
 
|-
Line 38: Line 38:
 
* [[Expand]]
 
* [[Expand]]
  
=File Meta Data=
+
=Carve Meta Data=
 
When Truxton carves this file, it can populate the following columns in the <code><nowiki>[</nowiki>[[File Table|File]]<nowiki>]</nowiki></code> table:
 
When Truxton carves this file, it can populate the following columns in the <code><nowiki>[</nowiki>[[File Table|File]]<nowiki>]</nowiki></code> table:
 
* <code>Created</code> - When the file was created
 
* <code>Created</code> - When the file was created
 
* <code>Modified</code> - When the file was last modified
 
* <code>Modified</code> - When the file was last modified
 
* <code>Name</code> - The name of the file
 
* <code>Name</code> - The name of the file

Revision as of 06:27, 15 January 2024

Details
Defined Constant Type_UTMP
File Type Value 997
Parent Type None
Carve Yes
Format Details No
Carve Meta Data Yes
MIME Type application/octet-stream
Filename Extension utmp

UTMP

Description

Records various unix system status items.

External links

Truxton Exploiters

This file type is handled by the following ETLs:

Carve Meta Data

When Truxton carves this file, it can populate the following columns in the [File] table:

  • Created - When the file was created
  • Modified - When the file was last modified
  • Name - The name of the file