rowingdude / analyzeMFT

MIT License
423 stars 117 forks source link

Additional rules #46

Open dkovar opened 7 years ago

dkovar commented 7 years ago

M - modified, B - birth, A - accessed:

If M < B then likely file copy Detected at B If M and B < A == volume file move