With the release of Windows 10 version 1803, came an exciting new forensics artifact: The Activity Timeline. The Activity Timeline is designed to remind users what they were up to in the recent past and help them pick up those activities right where they left off – even across multiple devices. In order to accomplish this feat, Windows stores a wealth of forensic goodness in a per-user SQLite databases.
Watch BlackBag's webinar as Dr. Vico Marziale, Senior Digital Forensics Researcher at BlackBag, walks investigators through:
– Configuration options for the Timeline
– How to find these databases
– How to decipher the contents of the databaseFollow along and you’ll have a shiny new tool in your forensics arsenal just waiting to be utilized in your next engagement!
About BlackBag Technologies:
BlackBag® Technologies offers innovative forensic acquisition and analysis tools for both Windows and macOS based computers, as well as iOS and Android mobile devices. Its forensic software is used by hundreds of federal, state, and local law enforcement agencies around the world, as well as by leading corporations and consultants, to investigate all types of digital evidence associated with both criminal, civil and internal investigations. BlackBag® Technologies also develops and delivers expert forensics training and certification programs, designed for both novice and experienced forensics professionals. To learn more, visit www.blackbagtech.com.