A Forensic Look at Windows® 10 Timeline Using SQL Queries to Exploit the Data

No ratings

Presented at TechnoSecurity&Digital 2020 by

The Windows 10 introduced a new feature named “Timeline” which has seen enhancements in subsequent updates to the Operating System in 2018 ~ 2020. This feature acts like a browser for all your recent file and web interactions on the local computer as well as mobile device and if enabled your additional trusted devices too. It provides a chronology view of interactions, which not only contains the websites visited but all documents you viewed or edited, the pictures you viewed as well as information of which machine it was interacted with last, most importantly the amount of time the user interacted with the item. During this session we will take a deep dive into the artifacts this feature creates and how they may be used by the system and interpreted in a forensic examination. Attendees will gain a deeper understanding of the complexities of this feature and a first hand look at the SQLite database containing all the artifacts while gaining an understanding of the cloud based synchronization issues. Attendees will be exposed to advanced SQL queries to interpret the data into a more human readable format.