In brief

What a forensic expert bases an artifact's interpretation on: someone else's results or one's own experiment. The main idea — a vendor's documentation diverges from the code for four different reasons, each shown through a Windows case: NTFS timestamps marked reserved, "scoped" shadow copies, the FAT specification, the prefetch files "OP-…pf". The method is "straight from the code": strings in the binaries, symbols, a decompiler, a black box. The talk is technical, with no product; there were no questions.

Key points

Tools, artifacts, technologies

No laws, articles, agencies or methodologies were mentioned; the terminology — "forensic expert", "interpretation of some artifacts, traces … anomalies", "expert experiment". There is one organizational storyline: Microsoft explained the scoped shadow copy to at least two customers in private replies, and this never made it into the public documentation.

Questions from the audience

There were no questions. The remark "At least it was honest. He never once said the word business" (the attribution is not established), then the moderator: "I think you've broken my audience again."

The speaker's position

Blind trust in documentation is a problem, not a solution: the justification has to be one's own experiment, and the source of truth is the code. Skepticism toward every text by someone else, Microsoft blogs included. He names the limitations himself: the NTFS example is extreme, the exclusion from copies works "with an asterisk", three of the four hypotheses about prefetch are "made up". The tone is a lecture with self-irony, with no selling.

Quotes