Location of the file on the disc
+diff --git a/objects.html b/objects.html index e962c93..7ab5622 100755 --- a/objects.html +++ b/objects.html @@ -480,6 +480,7 @@ body.book #toc,body.book #preamble,body.book h1.sect0,body.book .sect1>h2{page-b
Mactime template, used in forensic investigations to describe the timeline of a file activity.
++ + | ++mactime-timeline-analysis is a MISP object available in JSON format at this location The JSON format can be freely reused in your application or automatically enabled in MISP. + | +
Object attribute | +MISP attribute type | +Description | +Disable correlation | +Multiple | +
---|---|---|---|---|
file-path |
+text |
+
+ Location of the file on the disc + |
+
+ + |
+
+ + |
+
datetime |
+datetime |
+
+ Date and time when the operation was conducted on the file + |
+
+ + |
+
+ + |
+
file_size |
+text |
+
+ Determines the file size in bytes + |
+
+ + |
+
+ + |
+
activityType |
+text |
+
+ Determines the type of activity conducted on the file at a given time ['Accessed', 'Created', 'Changed', 'Modified', 'Other'] + |
+
+ + |
+
+ + |
+
filePermissions |
+text |
+
+ Describes permissions assigned the file + |
+
+ + |
+
+ + |
+
file |
+attachment |
+
+ Mactime output file + |
+
+ + |
+
+ + |
+
This relationship describes an object which controls another object.
['misp']
annotates
This relationships describes an object which annotates another object.
['misp']