Propeller Head Forensics

Minor update to Windows 8 Forensic Guide

Posted on: May 9, 2012

Hi everyone!
First of all, thank you so much for visiting my site, your e-mails, and spreading the word about my work.  The overwhelming support has been amazing; for some reason, I did not expect it – but thank you!

A couple of you have been kind enough to point out some minor errors.  Paul A. of Digital Detective e-mailed me that he has also been doing some research on Windows 8, but during the course of his research, he did not encounter any index.dat files:
“I’ve been examining Windows 8 myself (developer and consumer previews).  In my research, I haven’t found any index.dat files at all – rather the Internet history gets saved in various other files, including some in the ESE DB format.  I was just wondering what you did to get index.dat files generated, as I’m having no luck so far…?”

I double-checked my image and there was not a single instance of “index.dat”.  The lack of index.dat files is not due to lack of luck, but rather an error on my part of typing on auto-pilot.  I can only assume I saw the “dat” extension, even though I read “container.dat”, and typed “index.dat”.  So, there ended up being 3 or 4 instances of “index.dat” being mentioned, and if you see “index.dat”, either download the Windows 8 Forensic Guide that has been updated or cross it off if you’ve printed it out (it saves trees)!

The other great thing about Paul (and others!) contacting me is that it’s a great way to verify my research.  The e-mail traffic between Paul and I went on for a few days and he also found that his research revealed that the container.dat files in MSHISTdate-date are also 0 byte files.  One more thing he also shared was

“Where you see Internet Explorer folders that include the word ‘immersive’, then as you know that indicates you’ve launched IE from that hideous front end! ;-)  Try running IE from the more standard Windows desktop using the Quick Launch icon – you’ll find that the Travel log files are created in different folders, that don’t have immersive in their names!”

I hope this helps clear up some confusion (if there was any), and again, thanks again!


1 Response to "Minor update to Windows 8 Forensic Guide"

Great work so far, i’m really loving reading the other work that people have put into Windows 8 research! I’ve been doing a bit myself, here’s a post I made about some artifacts I came across relating to index.dat files that I haven’t seen popping up on any other websites yet. It relates to a file named WebCachev24.dat.

Do you haves something to say?

Fill in your details below or click an icon to log in: Logo

You are commenting using your account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Google+ photo

You are commenting using your Google+ account. Log Out / Change )

Connecting to %s

Enter your email address to follow this blog and receive notifications of new posts by email.

Join 77 other followers

Past Posts



Get every new post delivered to your Inbox.

Join 77 other followers

%d bloggers like this: