WinSearchDBAnalyzer Logo

WinSearchDBAnalyzer

0
Free
Visit Website

This tool can parse normal records and recover deleted records in Windows.edb, used in Windows Search. WinSearchDBAnalyzer can extract and analyze Windows.edb from live systems, showing more information than other tools, such as file categorization by extension, file hierarchy, and file contents. It can recover deleted records, works well on Windows 10, and can apply to UTC time, revealing data like Outlook Mail, OneNote, Internet History, Lnk list, Network Drive, Favorites, File and Folder Information, and Activity History.

FEATURES

ALTERNATIVES

Analyse a forensic target to find and report files found and not found in hashlookup CIRCL public service.

Magnet ACQUIRE offers robust data extraction capabilities for digital forensics investigations, supporting a wide range of devices.

DFIR ORC Documentation provides detailed instructions for setting up the build environment and deploying the tool.

Tool used for dumping memory from Android devices with root access requirement and forensic soundness considerations.

Toolkit for post-mortem analysis of Docker runtime environments using forensic HDD copies.

A shell script for basic forensic collection of various artefacts from UNIX systems.

A Python 2.x tool for memory analysis on Mac OS X systems with support for various OS versions and memory image export capabilities.

A Mac OS X forensic utility for ensuring correct forensic procedures during disk imaging.