EnCE · Domain 6
User Artifacts
About 12% of the exam
What user artifacts prove
- Presence of an account on the machine
- Interaction with specific files and folders
- Knowledge of a path or a name
- Sequence of activity within a session
- Preference and configuration choices
- Rarely, who was physically at the keyboard
Artifacts attach to an account, not to a person, so attribution always needs corroboration
Browsing artifacts
- History
- visits, counts and timestamps
- Cache
- page objects retained locally
- Cookies
- sessions and site preferences
- Downloads
- source address and saved path
- Bookmarks
- pages deliberately kept for later
- Session restore
- tabs open when the browser closed
- Autofill
- stored values keyed by field name
Reading browser evidence
- Record the exact address, not the page title
- Query parameters carry search terms
- Visit counts distinguish habit from accident
- A cookie does not prove a deliberate visit
- Extension install times explain new behavior
- Different browsers store data differently
Private browsing
- Downloaded files still land on disk
- Resolver cache records recent lookups
- Memory and swap hold page fragments
- Session data may survive a crash
- Document which locations were checked and empty
- Absence of history is not absence of activity
Documents and their metadata
Embedded metadata
- Author, company and last saved by
- Creation and last printed times
- Revision history and tracked changes
- Template and path remnants
Interim copies
- Auto recovery files hold unsaved states
- Temporary files remain after crashes
- Previous versions live in snapshots
- Cloud version history preserves earlier drafts
Hidden content
- Comments and deleted passages retained
- Embedded attachments inside the document
- Optional layers not shown by default
- Objects beyond the visible page count
The final saved version is only one state; revision data often shows what the author removed
Pictures and video
- Embedded metadata records device and settings
- Location tags may place the capture
- Editing software often rewrites the metadata
- Compare metadata against independent records
- Codec and container decide which fields exist
- Thumbnails may outlive the original file
Shell activity
- Shortcut files
- target path, volume and timestamps
- Jump lists
- recent and frequent per application
- Shell bags
- folders browsed, including removable media
- Recent documents
- files opened, ordered by recency
- Dialog paths
- locations chosen when saving
- Search history
- terms typed into the search box
Cloud sync clients
- Local database lists synced paths and status
- Selective sync limits what appears locally
- Server side logs give an independent check
- Placeholder files may hold no content
- Deleted items may sit in a cloud recycle area
- Note the account the client was signed into
Credential stores
- Browser credential stores are platform protected
- Password managers keep entry counts and titles
- Entry count overstates active accounts
- Stored values need the user key to decrypt
- Autofill records reveal identity details
- Handle recovered credentials with extra care
Building a user activity picture
- Identify the accounts
- Establish the session windows
- Order the artifacts
- Corroborate across applications
- State the confidence
Strong combinations
- Shortcut plus jump list plus document metadata
- Download record plus file creation time
- Search term plus subsequent visit
- Sync database plus server side activity
Weak on their own
- A cookie with no visit record
- A thumbnail with no original
- A recent entry with no open event
- A credential entry with no usage
Name the applications that support each entry, or the timeline is a claim rather than a finding
Notes, calendars and small apps
- Note creation times anchor other activity
- Calendar entries corroborate movement claims
- Task lists show intent and planning
- Clipboard history may retain copied text
- Sticky application data survives uninstalls
- Small databases often keep deleted rows
Reporting user artifacts
- State the account and the profile path
- Give the artifact source for every claim
- Distinguish opened from merely listed
- Note the application and version examined
- Explain what the artifact cannot establish
- Avoid naming a person without corroboration
Key artifacts
- Shortcut file
- path, volume serial, origin host
- Jump list entry
- access time and access count
- Auto recovery file
- unsaved content preserved automatically
- Thumbnail entry
- preview outliving the deleted image
- Autofill record
- field name paired with a value
- Sync database row
- path, status and last change
Know the order
- Resolve the account
- Set the time context
- Collect the artifacts
- Order and compare
- Corroborate across sources
- Report with limits
Two independent applications agreeing on the same act is what turns activity into evidence
Reference strip: user activity map
Web
- History, cache and cookies
- Downloads and bookmarks
- Session restore data
- Extension install times
Files
- Shortcuts and jump lists
- Shell bags for folders
- Recent document lists
- Save dialog paths
Documents
- Embedded author and timestamps
- Revision and tracked changes
- Auto recovery and temporary files
- Hidden layers and attachments
Media
- Capture device and settings
- Location tags where present
- Editing software rewrites
- Thumbnail and preview caches
Accounts and cloud
- Profile paths and identifiers
- Sync databases and selective sync
- Credential store entries
- Server side activity logs
Quick exam traps
- Trap: A cookie proves the user deliberately visited the site
- Trap: The document author field identifies who wrote it
- Trap: Private browsing leaves nothing recoverable
- Trap: A recent items entry proves the file was opened by that user
- Trap: Everything in the cloud account appears in the local sync folder
- Trap: A password manager entry count equals active accounts
- Trap: Location metadata on an image cannot have been edited
cybercertprep.com · original revision sheet written from the public body of knowledge