Direct answer
Look for two separate fingerprints, one for wiping and one for timestamp manipulation, then recover what you can despite them, and lean on independent sources rather than the tampered host alone to demonstrate that tampering actually happened. As an analyst investigating a live incident, if the case looks headed toward legal action, loop in digital forensics or legal early so evidence handling stays defensible from that point forward.
Approach
- Indicators of secure deletion: unallocated disk space that reads as uniformly random or shows a repeating fixed-byte pattern (a strong sign of a wiping pass, versus the more varied, partially-legible remnants of ordinary deletion); MFT (the Master File Table, the index NTFS keeps describing every file on the volume) or USN Journal (the rolling log the filesystem keeps of every file create, rename, and delete) entries showing a file was created and deleted with no recoverable content; execution artifacts (Prefetch, installed-program lists) for a known wiping or cleanup utility.
- Indicators of timestamp manipulation: a mismatch between a file's
$STANDARD_INFORMATION timestamps and its $FILE_NAME attribute timestamps. NTFS stores two sets of times for the same file: $STANDARD_INFORMATION is the set ordinary software is allowed to change and the one File Explorer and most tools show you, while $FILE_NAME is a second copy the filesystem keeps for its own bookkeeping that common tools do not touch. The two normally agree, so when a backdating utility rewrites only the visible set, the pair stops matching and that disagreement is the tell. You read both with a forensic MFT parser rather than in Explorer, since Explorer only ever shows you the first set. Also watch for timestamps that cluster suspiciously (many unrelated files sharing an identical time, consistent with a bulk "touch" operation) rather than the natural spread you'd expect.
- Recovering evidence despite this: unallocated space carving can sometimes recover partial content even after a wipe pass if the wipe didn't cover every sector touched by the file (slack space, meaning the leftover bytes between where a file ends and where its last disk cluster ends, alternate copies, backups); the USN Journal and Volume Shadow Copies (periodic point-in-time snapshots of the volume that Windows keeps for backup and restore) can independently corroborate a pre-tamper state for files whose live metadata was altered; centralized logging or endpoint telemetry collected before the tampering occurred is often the most reliable anchor.
- Demonstrating tampering in your report: show the mismatch or entropy anomaly as an observed fact, then show the independent corroborating source, then state your conclusion; a reviewer should be able to verify each step without taking your word for the last one.
Worked example
A host under investigation shows several dozen files with identical $STANDARD_INFORMATION timestamps set to a single date, an unnatural clustering for files that were supposedly created over weeks. Their $FILE_NAME timestamps, the internal copy the touch utility did not rewrite, still spread across several weeks, so the two sets contradict each other on the same files. A Volume Shadow Copy taken before the suspected tampering window shows different, more varied timestamps for the same files, directly contradicting the live metadata and pinning down that the change happened after the snapshot was taken. Separately, endpoint telemetry already forwarded to a central collector before the tampering shows the process that ran a bulk file-touch operation, tying the mechanism to the observed anomaly.
Trade-offs and pitfalls
Don't rely on the compromised host's own disk artifacts as your only evidence; wherever possible anchor to something collected independently and earlier. A wipe pass covering only part of the relevant free space is common (attacker time pressure, partial tool coverage), so absence of a full wipe pattern everywhere doesn't mean wiping wasn't attempted, check systematically rather than stopping at the first clean-looking region. If litigation becomes likely, hand off or coordinate with digital forensics early rather than continuing an informal incident-response process on evidence that will later need to hold up to a stricter chain-of-custody standard.