Digital Forensics Chain-of-Custody Hash Manifest & MACB Timeline Builder (2026)

Hash digital evidence files locally via WebCrypto (SHA-256, SHA-512, SHA-1), detect NTFS/ext4 MACB (Modified, Accessed, Changed, Born) timestomping anomalies (`$STANDARD_INFORMATION` vs `$FILE_NAME`), and generate NIST SP 800-86 Chain-of-Custody manifests.

Digital Forensics Chain-of-Custody Hash Manifest & MACB Timeline Builder — Interactive Console
Runs locally in your browser • Instant output
Hash Local Evidence Files in RAM (`window.crypto.subtle` SHA-256 + SHA-1)
Zero bytes leave your device. Select any file to append its cryptographic hash to the Chain of Custody.
[EV-01] C:\Windows\System32\svchost_updater.exe (294,912 B)
NTFS TIMESTOMP ANOMALY
SHA-256: 9f86d081884c7d659a2feaa0c55ad015a3bf4f1b2b0b822cd15d6c15b0f00a08
SHA-1: a94a8fe5ccb19ba61c4c0873d391e987982fbbd3
Modified (M): 2022-01-15T08:00:00.000Z | Birth (B): 2026-09-28T03:11:42.419Z
$SI Modified timestamp predates $FN Birth timestamp (Classic SetFileTime Timestomping)
[EV-02] C:\Users\admin\AppData\Local\Temp\dump_lsass.dmp (44,182,528 B)
MACB CHRONOLOGY VALID
SHA-256: 4b227777d4dd1fc61c6f884f48641d02b4d121d3fd328cb08b5531fcacdabf8a
SHA-1: e38ad214943daad1d64c102faec29de4afe9da3d
Modified (M): 2026-09-28T03:15:19.882Z | Birth (B): 2026-09-28T03:15:18.012Z
Consistent NTFS MACB chronology
Ready
Embed / Cite This Tool (Markdown & HTML)
GitHub / Reddit Markdown Badge[![Digital Forensics Chain-of-Custody Hash Manifest & MACB Timeline Builder](https://img.shields.io/badge/ZerosUniverse-Free_Tool-ff6a00)](https://www.zerosuniverse.com/tools/digital-forensics-chain-of-custody-timeline-builder/)
Blog / Documentation HTML Citation<a href="https://www.zerosuniverse.com/tools/digital-forensics-chain-of-custody-timeline-builder/">Digital Forensics Chain-of-Custody Hash Manifest & MACB Timeline Builder — ZerosUniverse</a>

2026 Quick-Reference Cheat Sheet & Benchmark Table: Digital Forensics Chain-of-Custody Hash Manifest & MACB Timeline Builder

Quick Answer & 2026 Technical Summary (digital forensics chain of custody hash generator)Updated 2026 Standard

MACB represents the four core file system timestamps: **M**odified (when file content bytes were last written), **A**ccessed (when file data was last read or touched), **C**hanged / MFT Entry Modified (when metadata such as permissions, filename, or attributes changed), and **B**orn / Created (when the file record was originally created on that volume). Use this interactive digital forensics chain of custody hash generator above to test macb timestamp forensics timestomping detector, dfir chain of custody evidence manifest builder, and ntfs standard information file name timestomp analyzer locally in your browser with zero server uploads.

Target Keyword Spec: digital forensics chain of custody hash generator | Modules: Zero-Upload Dual-Hash Evidence Locker (SHA-256 + SHA-512) • NTFS MACB Timestomping & Chronological Paradox Detector • NIST SP 800-86 / ISO 27037 Chain-of-Custody Manifest Generator
Primary Focus: digital forensics chain of custody hash generator
Core Capability: macb timestamp forensics timestomping detector
Privacy Mode: 100% Client-Side (Zero Upload)
Technical Parameter / ModuleStandard / Keyword SpecArchitecture & Validation RuleOperational Use Case (2026)
Zero-Upload Dual-Hash Evidence Locker (SHA-256 + SHA-512)macb timestamp forensics timestomping detectorDrop disk images, PCAPs, memory dumps, or log archives to compute cryptogra...Incident Response Evidence Intake & Write-Blocker Verification
NTFS MACB Timestomping & Chronological Paradox Detectordfir chain of custody evidence manifest builderCompare `$STANDARD_INFORMATION` (`$SI`) vs `$FILE_NAME` (`$FN`) MFT timesta...Hunting Anti-Forensic Timestomping in NTFS Master File Tables ($MFT)
NIST SP 800-86 / ISO 27037 Chain-of-Custody Manifest Generatorntfs standard information file name timestomp analyzerBuild court-ready Chain-of-Custody transfer logs with Case ID, Examiner Bad...Reconstructing File System Activity Across Copy, Move & Execution
Execution & Privacy Architecture100% Client-Side WebCrypto / JS Sandbox0 Bytes Sent to External ServersSafe for internal SOC & authorized lab artifacts
NIST SP 800-53 / OWASP AlignmentOWASP ASVS v4.0.3 / NIST CSF 2.0Deterministic Rule & Header VerificationMaps findings to actionable hardening controls
Cryptographic & Entropy StandardSHA-256 / AES-256-GCM / Argon2id≥ 128-bit Effective Security MarginMeets 2026 post-quantum & zero-trust baselines
In-Depth ZerosUniverse Tutorial

What is Cyberforensics and Its Role in Cybercrime in 2026

Read our complete step-by-step editorial guide, architecture breakdown, and defensive best practices on ZerosUniverse.

Read Full Guide

How to Use Digital Forensics Chain-of-Custody Hash Manifest & MACB Timeline Builder

01

Drop Evidence Files for Local WebCrypto Hashing (or Load DFIR Case Preset)

Drag and drop local evidence files to compute SHA-256 and SHA-512 digests in-browser, or load the built-in Ransomware Intrusion DFIR Case preset.

02

Inspect or Enter NTFS `$SI` vs `$FN` MACB Timestamps

Enter or inspect the Modified (M), Accessed (A), MFT Entry Changed (C), and Born/Created (B) timestamps for suspect artifacts.

03

Review Automated Timestomping & Nanosecond Truncation Alerts

Check for flagged `$SI < $FN` creation anomalies, zeroed 100-nanosecond tick fractional seconds (`.0000000`), and impossible chronological orderings.

04

Complete Custody Transfer Details & Export NIST Manifest

Fill in Case Number, Lead Examiner, Storage Location, and Transfer Custodian to download the signed Chain-of-Custody Markdown/JSON manifest.

Key Capabilities & Technical Architecture

Zero-Upload Dual-Hash Evidence Locker (SHA-256 + SHA-512)

Drop disk images, PCAPs, memory dumps, or log archives to compute cryptographic SHA-256 and SHA-512 integrity digests locally via native WebCrypto streams.

NTFS MACB Timestomping & Chronological Paradox Detector

Compare `$STANDARD_INFORMATION` (`$SI`) vs `$FILE_NAME` (`$FN`) MFT timestamps to detect `SetFileTime()` timestomping, zeroed sub-second nanosecond precision, and `Modified < Born` paradoxes.

NIST SP 800-86 / ISO 27037 Chain-of-Custody Manifest Generator

Build court-ready Chain-of-Custody transfer logs with Case ID, Examiner Badge, Write-Blocker Serial, Acquisition Method (dd/E01/AFF4), and cryptographic signature blocks.

Super-Timeline Event Sequencer & CSV/Markdown DFIR Exporter

Merge file system MACB timestamps with incident events into a normalized UTC forensic timeline and export formal markdown reports or Plaso-style CSVs.

Practical Use Cases

Incident Response Evidence Intake & Write-Blocker Verification

Verify that pre-acquisition and post-acquisition SHA-256 hashes match bit-for-bit and produce a standardized Chain-of-Custody handoff sheet.

Hunting Anti-Forensic Timestomping in NTFS Master File Tables ($MFT)

Spot malware binaries where an attacker used `timestomp.exe` or PowerShell `(Get-Item).CreationTime` to backdate `$STANDARD_INFORMATION` to 2019 while `$FILE_NAME` still reveals today's true creation time.

Reconstructing File System Activity Across Copy, Move & Execution

Determine whether a suspicious archive was freshly copied onto a volume (`Created > Modified`) or modified in place by analyzing MACB state transitions.

Frequently Asked Questions (FAQs)

What do the letters M-A-C-B stand for in digital forensics?+

MACB represents the four core file system timestamps: **M**odified (when file content bytes were last written), **A**ccessed (when file data was last read or touched), **C**hanged / MFT Entry Modified (when metadata such as permissions, filename, or attributes changed), and **B**orn / Created (when the file record was originally created on that volume).

How do forensic analysts detect NTFS timestomping using `$STANDARD_INFORMATION` and `$FILE_NAME`?+

Every file in an NTFS Master File Table (`$MFT`) stores two separate sets of MACB timestamps: one inside the `$STANDARD_INFORMATION` (`$SI`) attribute and another inside the `$FILE_NAME` (`$FN`) attribute. User-mode Windows APIs like `NtSetInformationFile` and `SetFileTime` (used by malware timestompers) can easily overwrite `$SI`, but `$FN` can only be modified by the Windows kernel itself. If `$SI Created` is 2021-01-01 while `$FN Created` is 2026-09-28, timestomping is proven.

Why does `Created (Born) > Modified` happen legitimately when copying a file?+

When you copy an existing file to a new volume or folder on Windows, the OS preserves the original content's `Last Write (Modified)` timestamp from months or years ago, but assigns the current clock time as the new file's `Created (Born)` timestamp on the destination volume. That makes the file appear 'modified before it was born'—a classic forensic indicator that a file was copied rather than created locally.

What is the 'Zeroed Nanoseconds' indicator in MFT forensics?+

NTFS stores timestamps in 64-bit FILETIME intervals of 100 nanoseconds (7 decimal places, e.g., `.4829103`). Older timestomping tools or manual scripts that pass second-level or millisecond-level timestamps leave the trailing fractional ticks as `.0000000`, which has a 1-in-10,000,000 chance of occurring naturally.

Are evidence files uploaded when computing SHA-256 and SHA-512 hashes here?+

No. Hashing uses your browser's hardware-accelerated `crypto.subtle.digest()` API directly on local `ArrayBuffer` slices. Zero bytes of evidence leave your workstation.