Table Of ContentARTIFACT REF ERENCE
4.3
CONTENTS
Windows 54
AdditionalSources 54
AndroidBackups 54
AppleDiskImages 54
iOSBackups 55
VirtualMachines 55
Chat 56
AdiumChat 56
AIM 56
AIMChatMessages 57
Chatroulette 57
ChatstepMessages 57
DiscordMessages 58
GoogleTalk 59
ICQ10Messages 59
ICQMessages 60
iMessageChats 60
iMessageMessages 61
KakaoTalkChatRooms-Windows 61
KakaoTalkContacts-Windows 62
KakaoTalkMessages-Windows 62
KakaoTalkPictures 63
KakaoTalkSharedPictures-Windows 64
Lync/OCCalls 65
Lync/OCFileTransfers 65
Lync/OCFragments 66
Lync/OCMessages 66
Mail.ru 66
Mail.ruChatNon-Carved 67
Mail.ruContacts 67
MessengerPlus!ChatLogs 67
mIRCChatLogs 68
MSNProtocolFragments 68
Omegle 68
ooVooChatHistory 69
ooVooContactList 69
ooVooPhoneBook 70
PalTalk 70
PidginAccelerators 71
PidginAccounts 71
PidginBuddies 71
PidginChat 72
PidginCustomSmileys 72
PidginOTRFingerprints 73
PidginOTRUsers 73
QQChat 74
SecondLifeChat 74
SkypeAccounts 74
SkypeActivity 75
SkypeCalls 76
SkypeChatMessages 77
SkypeChatsyncMessages 77
SkypeChatsyncMessagesCarved 78
SkypeContacts 78
SkypeFileTransfers 79
SkypeGroupChat 80
SkypeIPAddresses 80
SkypeMediaCache 81
SkypeSMS 81
SkypeVoicemails 82
TorChat 82
Trillian 83
WeChatMessages 83
WhatsAppMessages-Windows 84
WindowsLiveMessenger/MSN 84
WindowsLiveMessengerChat-Mac 85
WindowsViberCalls 85
WindowsViberChatMessages 86
WindowsViberContacts 86
WindowsViberGroupMembers 87
WindowsViberMessages 87
WorldofWarcraftChat 88
Yahoo!DiagnosticChats 89
Yahoo!Messenger(Mac) 89
Yahoo!Messenger-GroupChat 90
Yahoo!Messenger-Non-encryptedChat 90
Yahoo!MessengerChat 90
Yahoo!MessengerDiagnosticLogs 91
Yahoo!WebmailChat 91
YourPhoneContacts 92
YourPhoneDevices 92
YourPhonePictures 93
YourPhoneSMS/MMS 95
ZoomChatMessages 96
ZoomMeetingMessages 96
ZoomUserAccounts 97
Cloud 97
CarboniteLogFile 97
Dropbox 98
DropboxConfigurationData 98
Flickr 99
GoogleDocs 99
GoogleDrive 100
OneDrive 100
SharePointDiscussions 101
SharePointRecycleBin 101
SharePointSharedDocuments 102
Computer 102
MicrosoftTeamsActiivty 102
MicrosoftTeamsMessages 102
Documents 103
CalcDocuments 103
CSVDocuments 104
ExcelDocuments 105
HangulWordProcessor 105
ImpressDocuments 106
PDFDocuments 107
PowerPointDocuments 108
RTFDocuments 109
TextDocuments 109
WordDocuments 110
WriterDocuments 111
E-mail 112
CalendarEvents(ICS) 112
EML(X)Files 113
GmailEmailFragments 113
GmailWebmail 114
HotmailWebmail 114
HushmailFragments 115
HushmailInbox 115
MailinatorInboxAccess 115
MailinatorSnippets 116
MBOXEmails 116
OfflineGmailwebmail 117
OutlookAppointments 117
OutlookContacts 118
OutlookJournals 119
OutlookMessages 119
OutlookNotes 120
OutlookTasks 121
OutlookWebAppEmailFragments 122
OutlookWebAppInbox 122
OutlookWebmailInbox 122
WindowsMail 123
Yahoo!Webmail 123
Encryption 124
EncryptedFiles 124
Encryption/Anti-forensicsTools 125
Media 125
Audio 125
CarvedVideo 126
Pictures 126
RealPlayerLibraryAssets 128
RealPlayerVideoHistory 129
Videos 129
VLCRecentlyPlayedFiles 131
WebVideoFragments 132
Memory 132
ActiveNetworkInfo(sockets) 132
APIHooks(apihooks) 133
Clipboard(clipboard) 133
CommandHistory(cmdscan) 134
ConnectionScan(connscan) 134
DynamicallyLoadedLibraries(dlllist) 135
Files(filescan) 135
HiddenProcesses(psxview) 135
Hidden/ResidualModules(modscan) 136
Hidden/TerminatedProcesses(psscan) 136
ImageInfo(imageinfo) 137
LDRModules(ldrmodules) 137
LoadedKernelModules(modules) 138
MalwareFinder(malfind) 138
NetworkConnections(connections) 138
NetworkConnections(sockscan) 139
NetworkInfo(netscan) 139
OpenHandles(handles) 140
ProcessSecurityIdentifiers(getsids) 140
Processes(pslist) 140
Timeline(timeliner) 141
OperatingSystem 141
$LogFileAnalysis 141
.DS_StoreRecords 143
AmCacheDeviceContainers 143
AmCacheDriverBinaries 144
AmCacheDriverPackages 145
AmCacheFileEntries 146
AmCacheFileEntries-Legacy 147
AmCachePnpDevices 148
AmCacheProgramEntries 149
AmCacheProgramEntries-Legacy 150
AmCacheShortcuts 150
AutorunItems 151
CortanaPersonReminders 151
CortanaPlaceReminders 152
CortanaTimeReminders 152
FileAssociations 153
FileSignatureMismatch(Audio) 153
FileSignatureMismatch(Container) 154
FileSignatureMismatch(Document) 154
FileSignatureMismatch(Picture) 155
FileSignatureMismatch(Video) 155
FileSystemInformation 156
IMESuggestions(Japanese) 157
InstalledMicrosoftPrograms 157
InstalledPrograms 158
JumpLists 158
KeywordSearches 159
KnownDLLs 160
LatentWirelessGeolocatedWiFiHotspots 160
LNKFiles 161
LogMeInActivity 161
McAfeeLogs 162
MRUFolderAccess 163
MRUOpened/SavedFiles 163
MRURecentFilesAndFolders 164
MRURunCommands 164
MUICache 165
NetworkInterfaces(Registry) 165
NetworkProfiles 166
NetworkShareInformation 167
NetworkUsage-ApplicationData 167
NetworkUsage-Connections 168
OperatingSystemInformation 168
PrefetchFiles-Windows8/10 169
PrefetchFiles-WindowsXP/Vista/7 170
RecycleBin 171
RemoteDesktopProtocol 171
RemoteDesktopProtocolBitmapCache 172
ScheduledTasks 172
Shellbags 173
ShimCache 174
SRUMApplicationResourceUsage 174
SRUMEnergyUsage 175
SRUMEnergyUsage(LongTerm) 175
SRUMNetworkConnections 176
SRUMNetworkUsage 177
SRUMPushNotificationData 177
StartupItems 178
SystemServices 178
TeamViewerActivity 179
TimezoneInformation 179
USBDevices 180
UserAccounts 181
UserAssist 181
UsnJrnl 182
WindowsDefenderLogs 183
WindowsEventLogs 183
WindowsLogonBanner 184
WindowsNotificationCenter 184
WindowsStoredCredentials 184
WindowsTimelineActivity 185
Peer-to-Peer 186
AresDownloadFolder 186
AresDownloads 186
AresIncompleteDownloads 187
AresSearchKeywords 187
AresSharedFiles 187
BitcoinAddress 188
BitcoinDebugLogs 188
BitcoinLoggedQueries 189
CryptocurrencyClients 189
CryptocurrencyWallets 190
eMuleClients.metRecords 190
eMuleEmFriends.metRecords 191
eMuleGUIDs 191
eMuleKnown.metRecords 191
eMuleSearchKeywords 192
eMuleSharedFiles 193
eMuleSharedFolders 193
eMuleStoredSearches.metRecords 193
Frostwire 194
Frostwire.propsFiles 194
GigatribeChatMessages 195
GigatribeSharedFiles 195
LimerunnerSharedFiles 196
LimewireSharedFiles 196
Limewirev5.xSearches 196
Limewire/Frostwire4.xSearches 197
Limewire.propsFiles 197
LuckywireSharedFiles 197
ShareazaGUIDs 198
ShareazaLibraryFiles 198
ShareazaSearchKeywords 199
ShareazaSearchResults 199
TorrentActiveTransfers 199
TorrentFeeds 200
TorrentFileFragments 200
UsenetBinaryFiles 201
RefinedResults 202
RebuiltDesktops 202
SocialNetworking 202
BeboLiveChat 202
Facebook 203
FacebookChat 203
FacebookEmailSnippets 204
FacebookEmail 204
FacebookPages 205
FacebookStatusUpdates/WallPosts/Comments 205
Google+Chat 206
InstagramPictures 206
InstagramPosts 207
LINEPictures 207
LinkedInEmails 209
MySpaceChat-Messages 209
MySpaceChat-UserInfo 209
MySpaceInboxMessages 210
SinaWeiboCarvedSearches 210
SinaWeiboMicroblogs 210
SinaWeiboSearchHistory 211
Twitter 211
VKWallPosts 212
VKWebMessages 212
WebRelated 212
360SafeBrowserArchivedKeywordSearchTerms 212
360SafeBrowserArchivedWebHistory 213
360SafeBrowserAutofill 213
360SafeBrowserAutofillProfiles 213
360SafeBrowserBookmarks 214
360SafeBrowserCacheRecords 214
360SafeBrowserCookies 215
360SafeBrowserCurrentDownloads 215
360SafeBrowserCurrentSession 216
360SafeBrowserCurrentTabs 216
360SafeBrowserFavIcons 216
360SafeBrowserHistoryIndex 217
360SafeBrowserLastSession 217
360SafeBrowserLastTabs 218
360SafeBrowserLogins 218
360SafeBrowserSavedCreditCards 218
360SafeBrowserShortcuts 219
360SafeBrowserTopSites 219
360SafeBrowserWebHistory 219
360SafeBrowserWebVisits 220
AshleyMadison/BackpageAds/CraigslistAds/PlentyofFish 220
BingToolbar-MapHistory 221
BingToolbar-SearchHistory 221
Chrome 222
ChromeArchivedKeywordSearchTerms 223
ChromeArchivedWebHistory 223
ChromeAutofillProfiles 224
ChromeAutofill 224
ChromeBookmarks 225
ChromeCacheRecords 225
ChromeCookies 226
ChromeCurrentSession 226
ChromeCurrentTabs 226
ChromeDownloads 227
ChromeExtensions 227
ChromeFavlcons 228
ChromeHistoryIndex 228
ChromeKeywordSearchTerms 228
ChromeLastSession 229
ChromeLastTabs 229
ChromeLogins 229
ChromeSavedCreditCards 230
ChromeShortcuts 230
ChromeSyncAccounts 231
ChromeSyncData 231
ChromeTopSites 232
ChromeWebHistory 232
ChromeWebVisits 232
EdgeCacheData 233
EdgeExtensions 233
EdgeFavorites 234
EdgeLastSession 234
EdgeReadingLists 235
EdgeTopSites 235
Description:The GUID of the volume. VSN Decimal. The volume serial number in decimal notation. VSN Hex. The volume serial number in hexadecimal notation a google maps link to the sent location. For images the message can be empty or a blurb of text. Message Type. Identifies the type of message sent.