Windows® 10 Timeline Forensic Analysis

No ratings

Presented at TechnoSecurity&DigitalForensics 2019 by

The Windows 10 April 2018 update (1803) introduced a new feature named “Timeline” which has been further enhanced in subsequent updates to the Operating System in late 2018 and early 2019. This feature acts like a browser for all your recent file and web interactions on the local computer and if enabled your additional trusted devices too. It provides a chronology view of interactions, which not only contains the websites visited but all documents you opened or edited, the pictures you viewed and games you played as well as information of which machine it was interacted with. During this session we will take a deep dive into the artifacts this feature creates and how they may be used by the system and interpreted in a forensic examination. Attendees will gain a deeper understanding of the complexities of this feature and a first hand look at the SQLite database containing all the artifacts and understanding of the cloud based synchronization issues.