I’m working on the The Case of the Stolen Szechuan Sauce CTF and notice that the timestamps for extracted content like web history and shellbags are showing the incorrect times. Every other tool shows the relevant history artifacts at 03:23:41 UTC but Autopsy shows it at 07:23:41 UTC. I tried adding the image using the timezone in its
SYSTEM\ControlSet001\Control\TimeSoneInformation\TimeZoneKeyName registry value, PST8PDT, and then again at UTC. Either way it still shows the history as 07:23:41 UTC.
See below to see Browsing history view compared with Autopsy
Strangely though, the filesystem timestamps that I see Autopsy are the exact same as those I see in other tools. E.g. a file creation timestamp in shown in Autopsy is the same as what I see in other tools. This means that timezones are not being processed/displayed consistent between different artifacts.
One thing I’m curious about is if Autopsy is being affected by my laptop’s timezone. The host laptop where I’m running Autopsy system is currently at UTC-04:00 (before anyone says anything, I know this is bad practice. I do practice CTFs from my laptops that I use for day-to-day work. Real case-work is run from a server that is set to UTC).
Has anyone encountered something like this?