Skip to content

Commit 754c56a

Browse files
authored
Update README.md
1 parent 5596945 commit 754c56a

File tree

1 file changed

+26
-20
lines changed

1 file changed

+26
-20
lines changed

README.md

Lines changed: 26 additions & 20 deletions
Original file line numberDiff line numberDiff line change
@@ -17,8 +17,8 @@
1717
- Standalone ActivitiesCache.db<br>
1818
- CurrentUser's selected ActivitiesCache.db with matching registry (HKCU) device entries<br>
1919
- Standalone ActivitiesCache.db with offline NTUser.dat device entries<br>
20-
21-
Note1: Requires "[System.Data.SQLite](https://system.data.sqlite.org/index.html/doc/trunk/www/downloads.wiki)". If not available, it will download and install automatically.<br>
20+
21+
Note1: Requires "[System.Data.SQLite.dll](https://system.data.sqlite.org/index.html/doc/trunk/www/downloads.wiki)". <br>*If it's not available, it show prompt to download and install automatically.*<br> *Installation path:* `C:\Program Files\System.Data.SQLite\2010\bin\`<br>
2222
Note2: Runs on Windows 10 x64 <br>
2323

2424
* **ActivityTypes observed:**
@@ -42,18 +42,18 @@
4242
* **Device Types:** <br>
4343
(According to the Connected [Devices Platform specification](https://winprotocoldoc.blob.core.windows.net/productionwindowsarchives/MS-CDP/[MS-CDP].pdf) & observation)* <br>
4444

45-
- 0.Windows 10X *(dual screen)* device *(Observed)*
46-
- 1.Xbox One
45+
- 0.Windows 10X *(dual screen)* device *(Observed & Verified)*
46+
- 1.Xbox One *(Verified)*
4747
- 6.Apple iPhone
4848
- 7.Apple iPad
49-
- 8.Android device
50-
- 9.Windows 10 Desktop
49+
- 8.Android device *(Verified)*
50+
- 9.Windows 10 Desktop *(Verified)*
5151
- 11.Windows 10 Phone
5252
- 12.Linux device
5353
- 13.Windows IoT
5454
- 14.Surface Hub
55-
- 15.Windows 10 Laptop PC *(Observed)*
56-
- 16.Windows 10 Tablet PC *(Observed)*
55+
- 15.Windows 10 Laptop PC *(Observed & Verified)*
56+
- 16.Windows 10 Tablet PC *(Observed & Verified)*
5757

5858
* ### [WindowsTimeline Clipboard Text Carver *(ClipboardTextEntries.exe)*](https://github.com/kacos2000/WindowsTimeline/releases) ###
5959
![T](https://raw.githubusercontent.com/kacos2000/WindowsTimeline/master/Clips.JPG)<br>
@@ -75,7 +75,23 @@ ________________________________________________________________________________
7575
* Phones and phablets *(Screen sizes: 4'' to 5'' for phone, 5.5'' to 7'' for phablet)*<br>
7676
* Surface Hub devices *(Screen sizes: 55” and 84'')*<br>
7777
* Windows IoT devices *(Screen sizes: 3.5'' or smaller, Some devices have no screen)*<br>
78+
__________________________________________________________________________________________
79+
80+
* ### Documentation ###
81+
82+
- [WindowsTimeline.pdf](WindowsTimeline.pdf) - Documentation for the database and its entries. *Updated with information for the ~upcoming~ Win10 v1809 & v1903+ upgrades.* *Updated with Clipboard History info*
83+
- [A Forensic Exploration of the Microsoft Windows 10 Timeline](https://onlinelibrary.wiley.com/doi/abs/10.1111/1556-4029.13875) - (Journal of Forensic Sciences DOI:10.1111/1556-4029.13875) - *(Win10 1803)*<br>
84+
- [Exploring the Windows Activity Timeline, Part 1: The High Points](https://www.blackbagtech.com/blog/exploring-the-windows-activity-timeline-part-1-the-high-points/)<br>
85+
- [Exploring the Windows Activity Timeline, Part 2: Synching Across Devices](https://www.blackbagtech.com/blog/exploring-the-windows-activity-timeline-part-2-synching-across-devices/)<br>
86+
- [Exploring the Windows Activity Timeline, Part 3: Clipboard Craziness](https://www.blackbagtech.com/blog/exploring-the-windows-activity-timeline-part-2-clipboard-craziness/?utm_content=134912769&utm_medium=social&utm_source=twitter&hss_channel=tw-209890844)<br>
7887
__________________________________________________________________________________________
88+
89+
* **Related**
90+
91+
- [Win10 YourPhone app](https://github.com/kacos2000/Win10/blob/master/YourPhone/readme.md)<br>
92+
- [Win10 Notifications](https://github.com/kacos2000/Win10/blob/master/Notifications/readme.md).<br>
93+
__________________________________________________________________________________________
94+
7995

8096
**SQLite queries to parse Windows 10 (*[1803+](https://support.microsoft.com/en-us/help/4099479/windows-10-update-history?ocid=update_setting_client)*) Timeline's ActivitiesCache.db Database**
8197

@@ -112,18 +128,13 @@ ________________________________________________________________________________
112128
___________________________________________________________________________________________
113129

114130
#### (5/2019) ####
115-
[**>> Revised query <<**](https://github.com/kacos2000/WindowsTimeline/blob/master/Timeline.sql) for Windows Timeline - works with all versions (1803,1809,1903+) and is based on the smartlookup view #dfir. (Tested on Win10 pro 1903 *(Build 19023.1)*) <br>
131+
[**>> Revised query <<**](https://github.com/kacos2000/WindowsTimeline/blob/master/Timeline.sql) for Windows Timeline - works with all versions (1803,1809,1903+) and is based on the smartlookup view. (Tested on Win10 pro 1903 *(Build 19023.1)*) <br>
116132

117133
* **Windows versions (OSBuild*) supporting Timeline:**<br>
118134
- March 2019 Update (v1903 18875) .. <br>
119135
- October 2018 Update (v1809 - 17763)<br>
120136
- April 2018 Update (v1803 - 17134)<br>
121137

122-
* **Related**
123-
- [Win10 YourPhone app](https://github.com/kacos2000/Win10/blob/master/YourPhone/readme.md)
124-
- [Win10 Notifications](https://github.com/kacos2000/Win10/blob/master/Notifications/readme.md).
125-
126-
127138
___________________________________________________________________________________________
128139

129140

@@ -151,7 +162,7 @@ ________________________________________________________________________________
151162
* [Using Windows 10’s New Clipboard: History and Cloud Sync](https://www.howtogeek.com/351978/using-windows-10s-new-clipboard-history-and-cloud-sync/)<br>
152163

153164
**Tested on:**
154-
- [DB Browser for SQLite](http://sqlitebrowser.org/) 3.10.1,
165+
- [DB Browser for SQLite](http://sqlitebrowser.org/) 3.10.1+,
155166
- [SQLiteStudio](https://sqlitestudio.pl/index.rvt) as well as
156167
- [SQLite Expert Pro with the JSON1 extension](http://www.sqliteexpert.com/extensions/)
157168
- and Microsoft Windows 10 version [1803, 1903](https://support.microsoft.com/en-us/help/4099479/windows-10-update-history?ocid=update_setting_client) (OS builds from 17134.48 to 17134.254) and version 1809 (Insider's Build 17754.1) and 1903 (19023.1)
@@ -166,12 +177,7 @@ ________________________________________________________________________________
166177
![Delimiter Options](https://raw.githubusercontent.com/kacos2000/WindowsTimeline/master/e2.JPG)
167178

168179
and you will be presented with another window to select Folder and Filename to save the CSV file.
169-
__________________________________________________________________________________________
170180

171-
* ### Documentation ###
172-
173-
- [WindowsTimeline.pdf](WindowsTimeline.pdf) - Documentation for the database and its entries. *Updated with information for the ~upcoming~ Win10 v1809 & v1903 upgrades.*
174-
- [A Forensic Exploration of the Microsoft Windows 10 Timeline](https://onlinelibrary.wiley.com/doi/abs/10.1111/1556-4029.13875) - (Journal of Forensic Sciences DOI:10.1111/1556-4029.13875) - *(Win10 1803)*<br>
175181
__________________________________________________________________________________________
176182
* ### PowerShell scripts *(Win10 - 1803,1809,1903+)* ###
177183

0 commit comments

Comments
 (0)