Time Based Searches
So, let’s do some interesting searches. Let’s take a look at modified files leading up to that last day. The key word is modified:, as in modified:last week. This tool accepts dates as well as easy-to-use terms like yesterday, today, and last week. From the returned list of files, we see Mr. WonderCoder was busy, very busy, with the source code accessing files that weren’t normally touched. We may need to check more deeply into the changes when we have more than an hour. In fact, as we use the modifier "created:," we see a lot of new emails and expanded numbers of source code files. Moreover, the "created:" modifier points out a lot of neat tools were installed. We see new shortcuts in his menuing system. Why would he need to install a sniffer, Truecrypt (an encryption tool), and Nessus (a vulnerability scanner) in the week leading up to his surprise departure?