top | item 45716228

(no title)

nom | 4 months ago

Let me ground you a bit. This feature is 20 years old. The data is stored in NTFS alternate data streams.

https://en.wikipedia.org/wiki/Mark_of_the_Web

discuss

order

childintime|4 months ago

Wow, it contains forensic info:

"As of Windows 10, the contents [...] include the keys HostIpAddress, HostUrl, and ReferrerUrl.[...] they typically contain the domain name and exact URL of the original online download location".

phito|4 months ago

Interesting, thanks