Windows 10 (v1803+) ActivitiesCache.db parsers (SQLite, PowerShell, .EXE)
MPL-2.0 License
Bot releases are visible (Hide)
[Update Log]
MD5: 8551BD916973919503978168147CD4AB
SHA256: DC57AB744335A3F4EE0B499BDFF72F5D4B31D2D1C3979C3BBF4A7EAE82456576
Published by kacos2000 almost 2 years ago
Update :
MD5: F5416897612BFD3CEEC13808FE524E20
SHA256: 87AF5824E86C20F13E6D45595E98801A63D2FF9AF4DED011066DF754652F5780
Published by kacos2000 over 3 years ago
[Update Log]
Published by kacos2000 over 3 years ago
[Change Log]
Published by kacos2000 about 4 years ago
Update :
- Minor GUI fixes (e.g. dpi scaling)
- Some other minor fixes/updates
Published by kacos2000 about 4 years ago
- Retrieves (carves) current & deleted Clipboard text entries from an ActivitiesCache db or db-wal file.
- Displays offset of entry in the file & decoded text
- Allows Copy of a selection or all of the results
- Allows export to "|" separated CSV
Example:
- WindowsTimeline.exe: 15 clipboard text entries (SQLite query)
- ClipboardTextEntries.exe: 224 from the db & 19 from the db-wal
Update :
- Minor GUI fixes (e.g. dpi scaling)
Note: Duplicate entries could indicate that the clipboard text was in both 'Payload' & 'ClipboardPayload' fields.
Typically this occurs in synced entries, but this is not confirmed 100%.
Published by kacos2000 about 4 years ago
* Added Search option in Clipboard Text carver window to search the 'Copied Text' entries
* Added Search option in Application Execution list window to search both 'Application' & 'Description' entries
Published by kacos2000 about 4 years ago
Update :
- Added the option to search copied text items via a Search box:
Published by kacos2000 about 4 years ago
Note: Above 'availability' depends on the dB/registry entries
Published by kacos2000 about 4 years ago
Published by kacos2000 about 4 years ago
LEFT OUTER JOIN Activity ON ActivityOperation.Id = Activity.Id WHERE [O].[OperationType] <> 3
Published by kacos2000 about 4 years ago
NOTE: In previous 'WindowsTimeline parser' versions timestamps are in examiner's Local Time
Published by kacos2000 about 4 years ago
Update :
- Added tooltips
- Changed Base64 conversion from ASCII to UTF8.
Published by kacos2000 about 4 years ago
- Retrieves (carves) current & deleted Clipboard text entries from an ActivitiesCache db or db-wal file.
- Displays offset of entry in the file & decoded text
- Allows Copy of a selection or all of the results
- Allows export to "|" separated CSV
Example:
- WindowsTimeline.exe: 15 clipboard text entries (SQLite query)
- ClipboardTextEntries.exe: 224 from the db & 19 from the db-wal
Published by kacos2000 about 4 years ago
Published by kacos2000 about 4 years ago
Quite a few updates/improvements, plus:
Published by kacos2000 about 4 years ago
Published by kacos2000 about 4 years ago
Published by kacos2000 over 4 years ago
Published by kacos2000 over 4 years ago
Added support for Device Type 16 (Windows 10 Tablet PC)
Added option to view All the Devices in the selected NTUser.dat in a popup
Added some coloring to ease viewing large dB sets
Note:
If you need/want to manually download "System.Data.SQLite"
the location of the downloads is https://system.data.sqlite.org/index.html/doc/trunk/www/downloads.wiki
WindowsTimeline.exe looks for this file:
"C:\Program Files\System.Data.SQLite\2010\bin\System.Data.SQLite.dll"