Chivers, Howard Robert orcid.org/0000-0001-7057-9650 and Hargreaves, C (2011) Forensic Data Recovery From The Windows Search Database. Digital Investigation. pp. 114-126. ISSN 1742-2876
Abstract
Windows Search maintains a single database of the files, emails, programmes and Internet history of all the users of a personal computer, providing a potentially valuable source of information for a forensic investigator, especially since some information within the database is persistent, even if the underlying data are not available to the system (e.g.removable or encrypted drives). However, when files are deleted from the system their record is also deleted from the database. Existing tools to extract information from Windows Search use a programmatic interface to the underlying database, but this approach is unable to recover deleted records that may remain in unused space within the database or in other parts of the file system. This paper explores when unavailable files are indexed, and therefore available to an investigator via the search database, and how this is modified by the indexer scope and by attributes that control the indexing of encrypted content. Obtaining data via the programmatic interface is contrasted with a record carving approach using a new database record carver (wdsCarve); the strengths and weaknesses of the two approaches are reviewed, and the paper identifies several different strategies that may be productive in recovering deleted database records.
Metadata
Item Type: | Article |
---|---|
Authors/Creators: |
|
Dates: |
|
Institution: | The University of York |
Academic Units: | The University of York > Faculty of Sciences (York) > Computer Science (York) |
Depositing User: | Pure (York) |
Date Deposited: | 27 Jun 2013 00:14 |
Last Modified: | 06 Mar 2025 00:03 |
Published Version: | https://doi.org/10.1016/j.diin.2011.01.001 |
Status: | Published |
Refereed: | Yes |
Identification Number: | 10.1016/j.diin.2011.01.001 |
Related URLs: | |
Open Archives Initiative ID (OAI ID): | oai:eprints.whiterose.ac.uk:75046 |
Download
Filename: Forensic_Data_Recovery_From_The_Windows_Search_Database_preprint_DIIN328.pdf
Description: Forensic Data Recovery From The Windows Search Database