Login  |  Register
Bar Home         Features         Support         Purchase         Contact  
Link Exchange  - Article Details
ARTICLES
Windows Media Player Database CurrentDatabase_372.wmdb files
Brief introduction into the Windows Media Player program and analysis of currentdatabase_372.wmdb file and how to extract the content for review. This article may serve as an aid to forensic examiners or data recovery technicians.
Using FTK forensic software to detect SQLite Database Files
Using FTK forensic software to detect SQLite Database Files for processing in SQLite Forensic Reporter
Processing SQLite Databases using Templates (applicable to forensic analysis and data recovery)
Processing SQLite Databases using Templates (applicable to forensic analysis and data recovery). This article covers the processing of SQLite database files for forensic analysis, security auditing and data recovery purposes.
SQLite Forensic Reporter
SQLite Forensic Reporter is the most powerful tool available for analysing and reporting on the contents of SQLite database files on the market to date. With batch processing, advanced identification, decoding and reporting this is a perfect solution for computer & mobile phone examiners and data recovery technicians.
The use of Forensic Data Recovery Software in Different Sectors
These days, catching a criminal involves the use of highly sophisticated technologies which can generate vital evidence good enough to prove whether a person is really guilty or not. One of the known applications that can be taken under consideration in such cases is the forensic software or data recovery software.
STATISTICS
  • Active Links: 13
  • Pending Links: 1
  • Todays Links: 0
  • Total Articles: 26
  • Total Categories: 3
  • Sub Categories: 0

Windows Search Primer

Date Added: February 15, 2009 08:21:41 PM
Author: admin
Category: Documents

Windows Search is an indexed search engine released by

Microsoft for the Windows OS.

Windows search creates an index of the files on a computer,

the type of files indexed by Windows search can be determined

by the user.

Searches can be performed on the filenames, file contents and meta-data.

The default name for the main index database is ‘Windows.edb’

The default location for the database on Vista is:

ProgramData\Microsoft\Search\Data\Applications\Windows\Windows.edb

This folder may also contain transaction logs and other files required for the d

atabase/engine to function correctly as shown below.

 

Location

 

The user can determine what is indexed via the Control Panel

 

Control Panel > Indexing Options

 

Indexing Options

 

By reviewing the advanced options of the ‘Indexing Options’ screen you can determine

which file types can be indexed and to what extent. 

 

The screenshot below show that emails (.eml) on the example system will be indexed

to include both file properties and file content.

Properties

 

Microsoft includes a program called ‘esentutl’ which can be used to perform basic

maintenance and recovery and has 7 modes of operation displayed in the screenshot below:

 

Utility

 

The actual content of the Windows.edb can include but is not limited to: Filenames  Email addresses

Email message content  Documents (names and content)  Metadata  File path informationdDate/Time

information.

The content of the Windows.edb file can be extracted for further inspection using the Search Index Extractor, a forensic software utility part of the SC Suite.

Extractor

Ratings
You must be logged in to leave a rating.
Average rating: (0 votes)
Comments

No Comments Yet.


You must be logged in to leave a Comment.