Windows 10 (v1803+) ActivitiesCache.db parsers (SQLite, PowerShell, .EXE)
LEFT OUTER JOIN Activity ON ActivityOperation.Id = Activity.Id WHERE [O].[OperationType] <> 3
NOTE: In previous 'WindowsTimeline parser' versions timestamps are in examiner's Local Time
Update : - Added tooltips - Changed Base64 conversion from ASCII to UTF8.
- Retrieves (carves) current & deleted Clipboard text entries from an ActivitiesCache db or db-wal file.
- Displays offset of entry in the file & decoded text
- Allows Copy of a selection or all of the results
- Allows export to "|" separated CSV
Example:
- WindowsTimeline.exe: 15 clipboard text entries (SQLite query)
- ClipboardTextEntries.exe: 224 from the db & 19 from the db-wal
Quite a few updates/improvements, plus:
Added support for Device Type 16 (Windows 10 Tablet PC) Added option to view All the Devices in the selected NTUser.dat in a popup Added some coloring to ease viewing large dB sets
Note:
If you need/want to manually download "System.Data.SQLite"
the location of the downloads is https://system.data.sqlite.org/index.html/doc/trunk/www/downloads.wiki
WindowsTimeline.exe looks for this file:
"C:\Program Files\System.Data.SQLite\2010\bin\System.Data.SQLite.dll"