Skip to content

Glossary

ext4 crtime (Birth Time)

ext4 crtime is the file creation timestamp stored in extended inode fields, shown as Birth by stat and readable with debugfs on disk images.

crtime is the creation, or birth, time of a file on ext4. It is stored in the extended part of the inode, which exists on the default 256-byte inodes, with nanosecond resolution. Unlike mtime and atime, it cannot be changed with touch or the utimensat system call, which makes it valuable for detecting timestomping: a binary with an old mtime but a recent crtime was very likely planted or replaced recently.

On a running system, modern stat (coreutils 8.31 and later, using the statx system call on kernel 4.11 and later) shows it as Birth. On an image, debugfs reads it directly from the inode:

stat /mnt/evidence/usr/bin/sshd
debugfs -R 'stat <1835041>' /dev/loop0p1

Keep the caveats in mind. crtime records when that inode was created on this filesystem, so copying a file, extracting it from an archive or having an editor save by writing a new file and renaming it all produce a fresh crtime. Filesystems created with 128-byte inodes have no crtime. It can also be altered by someone who edits the raw inode with debugfs on an unmounted filesystem, which is rare but possible. XFS v5 has an equivalent creation time. See ext4 and XFS timestamps and super timelines with Plaso.