Chivers, Howard Robert orcid.org/0000-0001-7057-9650 (2018) Navigating the Windows Mail database. Digital Investigation. pp. 1-23. ISSN 1742-2876
Abstract
The Extensible Storage Engine (ESE) database is used to support many forensically important applications in the Windows operating system, and a study of how ESE is used in one application provides wider insights into data storage in other current and future applications. In Windows 10, WindowsMail uses an ESE database to store messages, appointments and related data; however, field (column) names used to identify these records are hexadecimal property tags, many of which are undocumented. To support forensic analysis a series of experiments were carried out to identify the function of these tags, and this work resulted in a body of related information about the Mail application. This paper documents property tags that have been mapped, and presents how Windows Mail artifacts recovered from the ESE store.vol database can be interpreted, including how the paths of files recorded by the Mail system are derived from database records. We also present examples that illustrate forensic issues in the interpretation of email messages and appointment records, and show how additional information can be obtained by associating these records with other information in the ESE database.
Metadata
Item Type: | Article |
---|---|
Authors/Creators: |
|
Copyright, Publisher and Additional Information: | © 2018 Elsevier Ltd. All rights reserved. This is an author-produced version of the published paper. Uploaded in accordance with the publisher’s self-archiving policy. |
Keywords: | Windows Mail Email Message Appointment Calendar ESE Database store.vol Unistore ESECarve |
Dates: |
|
Institution: | The University of York |
Academic Units: | The University of York > Faculty of Sciences (York) > Computer Science (York) |
Depositing User: | Pure (York) |
Date Deposited: | 10 Jul 2018 11:00 |
Last Modified: | 06 Mar 2025 00:05 |
Published Version: | https://doi.org/10.1016/j.diin.2018.02.001 |
Status: | Published online |
Refereed: | Yes |
Identification Number: | 10.1016/j.diin.2018.02.001 |
Open Archives Initiative ID (OAI ID): | oai:eprints.whiterose.ac.uk:133161 |
Download
Filename: Navigating_the_Windows_Mail_database_accepted.pdf
Description: Navigating the Windows Mail database - accepted
Licence: CC-BY-NC-ND 2.5