Command Line Switches
afind [dir] /f [filename] /ns=no subs /a after
/b before /m between
time format =
hfind [dir] /hd=find dir/system attribs /ns=no subs
sfind [dir] /ns=no subs
filestat [filename]
hunt [\\servername]
Screen Shots and Help
See Chris Brenton's excellent
auditing site using the Forensic Toolkit and NTLast.
System Requirements
Windows NT 4.0 SP3
16MB Memory
Administrator privileges
Audit log enabled with searchable records
Set NT command line buffer to 500 or more lines. 1200 or more lines works well
COMMAND PROMPT MUST BE A
MINIMUM OF 80 CHARACTERS
A REMINDER. AS STATED IN OUR LICENCE, WE PRESENT THESE
TOOLS AS IS. NO WARRANTY EXPRESSED OR IMPLIED. THIS TOOL IS UNSUPPORTED.
Pricing
FREE
Netscape users, please right click and
"save link as" to a local file.